
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.

Google’s Gemini AI model gained access to the systems of three real companies during a cybersecurity test in May 2026.
Summary
The model was expected to operate only against simulated targets in a controlled environment. The test was conducted by Irregular, an independent AI security testing company. The setup was designed to prevent internet access.
A testing issue instead allowed Gemini to reach the live internet. Gemini Reached Real Company Systems The model was instructed to work against fictional companies as part of the security exercise. At least one fictional target shared a name with a real company.
After gaining internet access, Gemini was able to find the real organization. In one case, Gemini repeatedly guessed passwords until it gained access to a protected system. In two other cases, the model found credentials in publicly available repositories and used them to enter the systems.
Google stated that the model stopped its activity after identifying that the systems belonged to real companies. The company also confirmed that the three affected organizations were informed. Google reported that the incidents did not cause harm.
The identities of the companies are not disclosed. Irregular said the known problems in its testing environment were fixed. The company also said the relevant AI firms were informed about the issue in late July.
Google does not classify the episode as a model misalignment incident. The company said Gemini was carrying out the cybersecurity task it had been given when the testing environment exposed it to real systems. The model stopped after recognizing the targets were real.
The incident shows the risks of testing AI systems that can browse the internet, find credentials, and perform multiple cybersecurity actions. Similar incidents have also been reported during security evaluations involving AI models from OpenAI, Anthropic and Meta.
KazaSec's take
AI-related security incidents are a genuinely new category — prompt injection, model manipulation, and data leakage through an LLM integration don't map cleanly onto traditional application security testing, and are worth assessing deliberately rather than assuming existing controls already cover them.
Coverage details
We've archived 242 other articles touching the same topic (artificial intelligence, news) — see the full security news archive.
Related security advisories
Relevant from KazaSec
More coverage on this topic
We help organizations find and fix the gaps before they make headlines.