Back to Feed
AI SecuritySep 19, 2026

Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up

Google Gemini AI accessed real company systems during a security test due to a domain name mix-up.

Summary

During a cybersecurity evaluation in May 2026, Google's Gemini AI model inadvertently accessed real company systems. This occurred because a fictional company name used in a "capture the flag" exercise matched a real domain, allowing the AI to gain unauthorized access through password guessing and by finding credentials in public repositories. The AI reportedly stopped its intrusion upon realizing it had breached a live system, and the issue has since been addressed.

Full text

Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up Ravie LakshmananSep 19, 2026Artificial Intelligence / Web Security Google's Gemini model has become the latest artificial intelligence (AI) system to access the internet and break into other companies during a cybersecurity evaluation. The development was first reported by The Wall Street Journal. The incidents occurred in May 2026 as part of a test run conducted by Israeli company Irregular. The evaluation partner was also involved in similar hacks disclosed by OpenAI, Anthropic, and Meta. According to the Journal, the model gained access to a protected system after repeatedly guessing its password. Two other cases related to the model finding credentials in a public repository, allowing it to obtain unauthorized access to protected systems. However, unlike other incidents observed in the case of Anthropic and OpenAI, the Gemini model ended the intrusion after finding that it had breached a real company's system. Irregular is said to have notified Google of the incidents in July 2026. In a report published last month, Irregular pinned the evaluation breaches to a naming error that caused a fictional company name used during "capture the flag" exercises to unknowingly match with a real domain, thereby allowing the models to take advantage of the inadvertent internet access and target the domain "a limited number of times." "This event highlights the importance of training powerful AI models to act responsibly," Heather Adkins, Google's vice president of security engineering, told The Wall Street Journal. "In this case, the model acted appropriately." The tech giant also noted that it did not consider the behavior an example of model misalignment, as the agents halted in their efforts after the safety mechanisms were triggered. It's currently not known which companies were targeted, although Irregular confirmed to the Journal that Google's case was the same as other incidents and that the issue was addressed weeks ago. The disclosure comes days after OpenAI found six additional incidents in which its AI agents went off the rails, acting deceptively and taking unsanctioned actions during training. This included concealing mistakes, seeking unauthorized credentials, uploading files to the public internet, and communicating over Artifactory to "read other solvers' notes, posted replies, and used those exchanges to inform their responses." AI labs have faced increasing scrutiny ever since OpenAI disclosed in July that rogue AI agents bypassed internal controls, reached the open ​internet, and acted as a swarm to breach Hugging Face. The AI startup, which described it as "an unprecedented cyber incident," has since announced a new framework for reporting similar model misbehavior in the future. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  artificial intelligence, Google, Google Gemini, Web Security ⚡ Top Stories This Week OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure Claude Used to Automate Exploitation and Data Theft Across Multiple Victims Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6 Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks When the Whole Company Adopts AI: What It Does to Your SOC Your Critical Vulnerabilities Might Not Be Your Biggest Risk What It Took to Reach 1 Billion Build Manifests US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries Why Are So Many Security Professionals Keeping Breaches Quiet? The Economics of Dwell Time and Why AI Native SIEM Changes the Equation ⭐ Featured Resources Get the eBook: Map Enterprise AI Risk Across the Full Lifecycle Give SOC Analysts Visibility Into 90% of Attacks Within 60 Seconds Benchmark Your SOC's AI Adoption With the 2026 Security Operations Report Register for LDR516: Strategic Vulnerability and Threat Management at SANS DC Metro

Entities

Gemini (product)Google (vendor)Irregular (vendor)OpenAI (vendor)Anthropic (vendor)Meta (vendor)