Security · September 21, 2026
Also published in Português (Brasil)
Gemini Accidentally Breaches 3 Companies During Security Test
Google Gemini reportedly accessed the systems of three real companies while undergoing cybersecurity testing. This incident occurred in May 2026 but was only revealed to the public in September.
The testing was conducted by AI security company Irregular using a capture the flag (CTF) scenario. Gemini was tasked with finding information and completing security challenges in a simulated environment.
Problems arose because Gemini inadvertently gained internet access. Surprisingly, the fictitious companies targeted in the tests had names identical to real companies.
As a result, Gemini exited the simulated environment and interacted with the systems of actual companies.
According to reports, there were three separate incidents. In one case, Gemini repeatedly attempted to guess passwords, successfully accessing the system of a real company.
In the other two cases, Gemini uncovered information about fictitious companies online. This search led it to a public code repository that contained credentials belonging to real companies.
Gemini then used those credentials to attempt to complete the testing tasks and successfully entered the systems of the companies.
However, Gemini ultimately ceased its activities upon realizing the targets it accessed were real companies, not part of the simulation. The names of the three companies were not disclosed.
Google stated that no damage was caused to the three companies. The company also noted that the version of Gemini used in the testing was not its latest model.
Irregular informed Google about the incidents at the end of July. Google then stated it had notified the affected companies and federal authorities.
Google did not categorize the incidents as examples of AI misalignment, reasoning that Gemini stopped when it recognized the accessed systems were real.
Nonetheless, this case highlights new challenges in the development of AI agents. When AI is given internet access and the ability to perform various actions independently, small errors in testing environments can lead to interactions with systems outside the intended targets.
The Gemini case arises amid growing attention to the capabilities of AI agents to perform cybersecurity tasks automatically.