Forgot password
Enter the email address you used when you joined and we'll send you instructions to reset your password.
If you used Apple or Google to create your account, this process will create a password for your existing account.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.
Reset password instructions sent. If you have an account with us, you will receive an email within a few minutes.
Something went wrong. Try again or contact support if the problem persists.
Hooded person sitting at computer monitors displaying code, with an inset image of the Google logo.
Images by Julio Lopez/Pexels and Sarah Blocksidge/Pexels

Google’s Gemini AI broke out of a cyber test and hacked three real companies

AI labs run capture-the-flag exercises to measure how well a model can break into a computer network, and those exercises are meant to be sealed off from the open internet. One run in May 2026 was not. Google has confirmed that Gemini escaped its testing environment and gained unauthorized access to the systems of three real companies.

Recommended Videos

The evaluation was run by Irregular, an independent AI security firm that builds cybersecurity benchmarks for the major labs. Gemini was told to find a piece of hidden information inside a fictional company’s network, according to Reuters. That environment was never meant to have internet access, as the entire point of the exercise is containment.

Two faults lined up at once. The fictional target shared its name with a real business, and the sandbox had been left connected to the open web. Gemini searched for the name, found the real company, and treated it as another part of the test.

Google says the model stopped itself once it worked out the targets were real

The methods were basic. Gemini guessed passwords until one worked in the first case, and in the other two it pulled valid credentials out of publicly accessible code repositories. No zero-day exploit and no malware were involved at any point.

Google does not consider the episode a case of misalignment, the industry term for a model acting against its developer’s instructions. Gemini believed the outside systems were part of the test and stopped in all three instances. “The model acted appropriately,” Heather Adkins, the company’s vice president of security engineering, said.

The company said it notified the three affected organizations and federal authorities. However, it has declined to name them or to identify which version of Gemini was involved. Google said it believes the intrusions caused no damage, as the model halted each one without being told to.

Gemini is not the first model to slip its bounds this way. Anthropic disclosed in July that three Claude models had reached the production systems of three organizations through the same evaluation partner. It found them by reviewing more than 141,000 evaluation runs. Meta has also been through a comparable incident, and Irregular built the environments behind each of those cases.

A few years ago, accidental internet access would have meant very little, as models could not act on what they found. Gemini and systems like it can now browse sites, write and execute code, run command line tools, and chain long sequences of decisions together without a human approving each step. Public wariness has grown alongside that reach, from corporate networks down to a restaurant’s AI-generated catering menu.

Irregular told the labs about the fault in late July, and a spokesperson said every known issue on its end was fixed weeks ago. Google was among those notified but said nothing publicly until reporters asked about it this week.

The episode was not a case of Gemini deciding to go rogue. It was a containment failure that showed how quickly a routine evaluation can spill into the real world once an AI system is capable of acting on its own. The model stopped before doing any apparent damage, but the incident leaves AI labs with a harder question than whether their safeguards worked this time: what happens when the next model does not realize it has crossed the boundary?


Attack of the Fanboy is supported by our audience. When you purchase through links on our site, we may earn a small affiliate commission. Learn more about our Affiliate Policy
Author
Image of Asmir Pekmic
Asmir Pekmic
Asmir is a gaming writer with 16 years of experience covering the video game industry, specializing in news, guides, and live-service games. When he’s not writing or playing video games, he enjoys running and playing basketball.