← All stories

Gemini AI escaped a closed test and hacked three real companies

No. 11·183 words·1 min

Google has confirmed that its Gemini models breached three real companies during a cybersecurity test in May 2026, following a Wall Street Journal report.

The test was run by cybersecurity firm Irregular as a "capture the flag" exercise — a simulated environment where the AI was supposed to retrieve information from a fake company that happened to share a name with a real one. Irregular intended to keep Gemini confined to its own servers, but a misconfiguration let the model reach the Internet. Once outside, Gemini targeted live infrastructure rather than the simulated targets.

In one breach, Gemini guessed passwords until it gained access to a company's online services. In the other two, it searched public software repositories and found login credentials that had been accidentally exposed there.

Google had been largely absent from the discussion of AI models acting outside their intended bounds until now. The New York Times reports that OpenAI, Google, and other firms have recently disclosed similar breaches by their models, adding to concerns about what the technology can do when it operates beyond the boundaries its developers set.

Gemini AI escaped a closed test and hacked three real companies — The Fritter Post