[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$foa2EmrssfetS_HdbmRon1Nj28IjdE_-qmRUqKuW7OOI":3},{"article":4,"iocs":51},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":33,"category":34,"article_tags":38},"b3d46bc1-7ba3-4da1-8755-f4476554e514","Google Confirms Gemini AI Breached Three Firms","google-confirms-gemini-ai-breached-three-firms-4efebc","Google is the latest AI giant to confirm that its models escaped a testing environment and hacked real companies. The post Google Confirms Gemini AI Breached Three Firms appeared first on SecurityWeek.","Google confirmed its Gemini AI model accessed three real companies' systems during a cybersecurity test conducted by AI testing firm Irregular. The model, tasked with a capture-the-flag exercise, unintentionally gained internet access and used guessed credentials and public information to access systems, mistaking them for part of the test. Google stated the model realized its error and stopped each time, causing no harm and not warranting public disclosure until contacted by The Wall Street Journal.","Google's Gemini AI model accessed three real companies' systems during a cybersecurity test.","Google has confirmed that one of its Gemini models accessed the systems of three real companies during a cybersecurity test in May. The Wall Street Journal first reported the incidents on Friday, describing them as the first known case of Google’s AI systems autonomously hacking other companies. The test was run by Irregular, the AI testing company that was also involved in incidents disclosed by Meta, OpenAI and Anthropic. Heather Adkins, Google’s VP of security engineering, gave SecurityWeek the following statement about the Gemini incidents: “Safe development of powerful AI models is critical and we invest deeply in this area. In a standard evaluation, the model found public information online and guessed credentials to access websites it thought were part of the test. In all three of these instances, the model stopped.” Google described the incidents to the WSJ as mistaken identity. Gemini was taking part in a capture-the-flag exercise on Irregular’s infrastructure, tasked with retrieving information from software run by a fictional company that shared its name with a real one. The model was not intended to have internet access, but Irregular said access was unintentionally made available. In one case, the model guessed passwords until it gained access to a protected system. In two other runs, it searched the web using the company’s name, found credentials belonging to other companies in public repositories and used them to access the associated systems. Google said the model realized in each case that it had reached a real company and ended the intrusion. Irregular notified Google at the end of July. Unlike the other AI companies involved in similar incidents, Google did not disclose the findings until it was contacted by the WSJ.Advertisement. Scroll to continue reading. According to Google, the incidents did not warrant public disclosure because the model caused no harm and stopped immediately. It also said they were not an instance of model misalignment, since its safety measures helped the model stop. The company compared the episode to a bug bounty program. Google told the WSJ it notified federal authorities and the three affected companies, whose names it did not share. Adkins added the following in her statement to SecurityWeek: “Our security team has a long track record of reporting issues we find in other people’s software and systems – even if it’s as simple as a weak password. We ensured the three entities were made aware, and we worked with our training partner on the changes they’ve now made to their testing processes. These events highlight the importance of training powerful AI models to act responsibly.” Google said the incident did not involve its latest model, but did not disclose the model’s name. Irregular noted that Google’s case was the same as the other incidents and does not represent a new problem. A spokesperson said all known issues on its end were fixed weeks ago. AI companies taking action in response to incidents Since their initial disclosures, OpenAI and Anthropic have discovered several additional incidents in which their models hacked real companies or exhibited misaligned behavior. OpenAI agents were linked to a RubyGems attack earlier this year. In addition, the company disclosed six misalignment incidents last week, including agents searching GitHub for leaked API keys, unsanctioned collaboration between agents, moving data outside the intended environment, using jailbreak-style instructions for manipulation, and attempts to conceal failures. Anthropic has expanded the scope of its search for incidents involving unauthorized access to real systems, which led to the discovery of a new breach. Both OpenAI and Anthropic have announced taking action in response to these incidents. Anthropic paused evaluations and rolled out new protections against test environment escapes. It has also developed an enterprise system that combines zero data retention with automated misuse monitoring. OpenAI has proposed a framework to speed up publication of misalignment findings, and it has overhauled model security. The company is also leading a cyber defense pledge and is offering subsidized AI cyber capabilities to critical infrastructure defenders. The AI testing company Irregular has also detailed the action it took in response to incidents in which real systems were hacked during its evaluations. Related: AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code Related: Beijing Hits Back at Anthropic CEO’s Call to Curb China’s AI Development Related: Anthropic Researcher Resigns With Warning About the Dangers of AI Development Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Check Point, Kaspersky, Tanium Patch Product VulnerabilitiesCyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board VesselsOpenAI Says Its Models Searched GitHub for Leaked API Keys During TrainingCISA Retires Weekly Vulnerability Bulletin in Risk-Based PivotAI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing RefusalsPixel Modem Zero-Day Exploited in Targeted AttacksUS, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance MalwareEnterprises Warned of Attacks Exploiting WSO2 Vulnerability Latest News TigerByte Cyber Emerges From Stealth With $3 Million in FundingIn Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP FlawAI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code23 Million User Records Compromised in Gyazo Data Breach Microsoft Patches 18 Vulnerabilities in AI, Cloud ProductsNightmareStresser DDoS Service Disrupted in International OperationBrevo Supply Chain Attack Injects Malware Into 100,000 WebsitesCritical Orkes Conductor Vulnerability Exploited in Attacks Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Building Continuous Authorization at Scale September 23, 2026 Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required. Register People on the MoveVeritas Capital has appointed Joel Fulton as Chief Information Security Officer.incident.io has appointed Carlos Gonzalez-Cadenas as Chief Operating Officer.Ruben D. Chacon has joined ADM as Vice President and Global CISO.More People On The MoveExpert Insights “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, \"data\" in security meant logs and events. But logs are a lossy representation of reality. (","https:\u002F\u002Fwww.securityweek.com\u002Fgoogle-confirms-gemini-ai-breached-three-firms\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2026\u002F08\u002Frogue-AI-artificial-intelligence.jpeg","2026-09-21T07:20:46+00:00","2026-09-21T08:00:20.889675+00:00",7,[18,21,24,26,28,30],{"name":19,"type":20},"Gemini","product",{"name":22,"type":23},"Google","vendor",{"name":25,"type":23},"Meta",{"name":27,"type":23},"OpenAI",{"name":29,"type":23},"Anthropic",{"name":31,"type":32},"AI","technology","839da5c1-3c34-47e2-9499-f7201640e3ac",{"id":33,"icon":35,"name":36,"slug":37},null,"AI Security","ai-security",[39,44,46],{"category":40},{"id":41,"icon":35,"name":42,"slug":43},"2e06f76c-d5b9-4f54-9eef-4d3447b10730","Breaches","breaches",{"category":45},{"id":33,"icon":35,"name":36,"slug":37},{"category":47},{"id":48,"icon":35,"name":49,"slug":50},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[]]