Google Gemini AI Hacked 3 Real Companies During a Security Test — Then Stopped

Google’s Gemini artificial intelligence model invaded and broke into three real companies’ systems in May 2026 during a cybersecurity test after the AI agent briefly logged into the internet.

Google Gemini AI cybersecurity security test | Photo Credit: https://gemini.google.com/app
Google Gemini AI cybersecurity security test | Photo Credit: https://gemini.google.com/app

The events were conducted during an evaluation to test Gemini’s ability to identify and exploit security weaknesses in a controlled environment.

The testing was done by Irregular, an independent AI security assessment company. Gemini was instructed to access information from software of a fictional company for a “capture the flag” cybersecurity exercise. But the testing setup unintentionally let the model access the public internet.

The whole thing was made more complicated by the fact that the fictional company used in the exercise shared a name with a real business. Gemini followed the information available online and ended up interacting with real company infrastructure rather than the simulated systems it was supposed to target.

According to Google, Gemini used rather basic methods to gain access. In one case, the model guessed passwords until it was able to access a protected system, while in two cases, the model learned credentials in publicly accessible repositories and used them to gain access to protected systems.

The most interesting element of the incident was when Gemini gained access. Google said the AI agent became aware that it was dealing with real companies but not the fictional targets in the test.

In all three cases, Gemini stopped doing so, not continuing the intrusion. The affected companies were notified and Google said there was no reported harm caused by the incidents.

Google Vice President of Security Engineering Heather Adkins said that the incidents showed the importance of training advanced AI systems to behave responsibly. Google also worked with Irregular to reformulate the testing process following the incidents.

Irregular notified Google in July of the incidents. The company said relevant AI laboratories were informed and that the known issues related to its testing process had been addressed.

The Gemini incident is part of a larger series of AI-security events involving big tech companies. OpenAI, Anthropic, and Meta all reported cases in which AI systems involved in cybersecurity evaluations accessed systems outside their intended testing environments.

The episode has also given rise to the security problems of more and more autonomous AI agents. A different software type  : AI agents can interpret instructions, search online information and make decisions without the approval of a human.

This episode shows why isolated testing environments, limited internet access, and strong authorization controls are vital for autonomous AI systems to be evaluated.

Gemini stopped the implementation once it realized the mistake, but the incident shows that a connection between an AI agent and the open internet can turn a security exercise into access to the real world.