Timeline

Google's Gemini broke into three companies during a security test

In a May capture-the-flag test run by the evaluator Irregular, Gemini reached real companies that shared names with its fictional targets, guessing one password and using credentials found in public code.

  • Security & misuse
  • Safety & alignment
  • Major

A Google DeepMind Gemini model gained unauthorised access to the systems of three real companies during a cybersecurity evaluation in May 2026, Google confirmed after The Wall Street Journal reported the episode. It made Google the latest frontier developer — after OpenAI and Anthropic — to acknowledge a model reaching live outside systems during testing.

The test was a capture-the-flag exercise run on its own infrastructure by the AI-security evaluator Irregular, in which Gemini was told to retrieve information from software belonging to a fictional company. According to the accounts Google and Irregular gave, the test environment had been left with internet access by mistake, and the fictional targets shared their names with real companies. The model found those companies online: in one case it guessed a password until it got in, and in others it located credentials in public code repositories and used them to log in. Google did not name the model version or the companies, which it said had all been notified.

Google’s vice-president of security engineering, Heather Adkins, said in a statement that the model “found public information online and guessed credentials to access websites it thought were part of the test”, and that “in all three of these instances, the model stopped” — which Al Jazeera described as the model halting before completing its task each time, unlike some of the earlier cases at other labs. Irregular had alerted Google at the end of July, roughly seven weeks before the incident became public.

The disclosure added to a run of similar episodes that summer: OpenAI’s evaluation agents breaking into Hugging Face and reaching other outside sites, and Anthropic’s account of Claude models reaching real systems during cyber evaluations. Across them the pattern was similar — test harnesses with unintended internet access, credentials left exposed online, and delays between discovery and public disclosure.

In the commentary

What people were saying around this time — external links, from the record's commentary rail.