Google says Gemini accessed three companies in a flawed security test
Sunday, September 20, 2026
Google says its Gemini model gained access to systems at three real companies during a May cybersecurity exercise run by outside tester Irregular. The test was meant to keep Gemini inside a simulated challenge, but a configuration mistake gave it web access; the model then used public information, including exposed login details in two cases and a guessed password in another, because it mistook real systems for test targets. Google says Gemini stopped in each case, no damage was found, and the companies were notified. This was a testing failure rather than a reported attack campaign, but it shows how AI systems that can take multistep actions can turn a small safety lapse into real-world access—a problem other AI labs have also disclosed.
Did you like the content?
