Google's Gemini AI Hacked Three Companies in Security Test: What Happened?
Google Gemini accessed the systems of three real companies during a May 2026 cybersecurity test. Know what happened, how it gained access, and why it matters.
Google's Gemini AI Hacked Three Companies in Security Test: Google Gemini is an artificial intelligence (AI) model that is developed by Google. The AI model of Google Gemini accessed the computer systems of three real companies during a cybersecurity test in May 2026.
Gemini unexpectedly accessed the systems of three real companies while it was supposed to work inside a controlled testing environment. Google confirmed the incidents after reports about the tests emerged in September. The testing was conducted with Irregular, an AI security evaluation company.
What Happened?
It was a cybersecurity exercise in which Gemini was being tested through a capture-the-flag game. The AI was to play against an imaginary company in a simulated environment.
The testing setup was set up in such a way that Gemini accidentally had internet access. The fictional company was also named the same as a real company. Then, rather than remaining within the test environment, Gemini engaged with Real Systems.
SCOOP: Google's Gemini model hacked three companies as part of a May cybersecurity evaluation conducted by the testing company Irregular. Google was notified about the hacks in July, but didn't disclose them until we reached out this week.
— Erin Woo (@erinkwoo) September 18, 2026
w @bobmcmillan:https://t.co/ohjbpyfVGg
Key Facts About Google Gemini Security Test
| Aspects | Details |
| AI Model | Google Gemini |
| Incident | Accessed three real companies' systems |
| Testing period | May 2026 |
| Security tester | Irregular |
| Type of test | Cybersecurity evaluation |
| Main problem | Unintended internet access |
| Method | Password guessing and finding exposed credentials |
| Number of companies affected | 3 |
| Did Gemini continue after access? | No |
| Were the companies informed? | Yes |
How Did Google Gemini Access the Companies?
The cyber exercise scenario was based on a fictional company. Gemini was supposed to be able to locate information from the simulated company's systems.
However, the AI has accidentally had access to the internet during the test. In one instance the fictional company's name was the same as the name of a real company. The goal of Gemini was thus to connect to a real system, but instead, it connected to a test environment.
Once it did guess passwords to get into a protected system. In two other cases it discovered credentials in a public online repository, which it used to gain access to protected systems.
Why Is This Incident Important?
Google said Gemini paused its operations when it identified itself as having interacted with actual companies instead of the "fictional" ones. Three affected companies were notified and changes were implemented in the testing procedure.
Why is this significant in the context of AI and Cybersecurity?
AI models are starting to be able to do what was once human-only tasks such as searching information, analysing computer systems and finding security weaknesses.
This is why AI cybersecurity tests require isolated environments, restricted access to the Internet and appropriate security measures.
Quick Points
-
Gemini is an AI model created by Google.
-
The cyber security test was conducted in May of 2026.
-
The evaluation was done by Irregular on behalf of Google.
-
The three real companies were able to be accessed by Gemini.
-
The AI was used to guess passwords and publicly available credentials.
-
The test environment was inadvertently provided with Internet connectivity.
-
After realizing that the systems were those of actual companies, Gemini ceased operations.
Conclusion
This is a crucial instance of the intersection of AI and cybersecurity, as exemplified by the Google Gemini security test. It also demonstrates the need to test AI systems in safe and controlled environments prior to allowing access to real computer networks.
Prabhat Mishra is a Subject Matter Expert and digital journalist with an extensive background in the competitive exam landscape and over 4 years of experience in education, national and international news, and current affairs. Over his tenure with top knowledge platforms like Mentorship India, IAS BABA, IAS SARTHI, and now Jagran Josh, he has a deep understanding of government exams like UPSC and State PCS, including UP and Bihar, as he has already qualified for the UPPCS 2022 Mains and Bihar 68th Mains. With his core expertise in history, polity, geography & current affairs, he specialises in creating well-researched, aspirant-centric content and simplifying complex topics for competitive examinations.