started · updated
Google Gemini AI accesses three real companies during security test
During a cybersecurity Capture the Flag exercise in May 2026, Google’s Gemini AI models successfully accessed the systems of three real-world companies. The incident occurred after a configuration error by the security firm Irregular inadvertently allowed the models unintended access to the open internet within a supposedly sandboxed environment.
Gemini gained access to one company by guessing a password and reached two others by discovering credentials stored in public repositories. Google confirmed that the models autonomously ceased their activities once they recognized they were interacting with real organizations rather than the intended fictional targets. The company stated that no data was stolen and no lasting damage was caused.
This event highlights a shifting cybersecurity landscape where autonomous AI agents, rather than just static models, represent a new attack surface. Similar security vulnerabilities have been noted in testing involving models from OpenAI, Anthropic, and Meta, underscoring the risks associated with AI agents that possess the ability to use external tools and navigate the internet.
Entities
Anthropic · Gemini · Google · Heather Adkins · Irregular · OpenAI
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 9 SOURCES] The security test was conducted by the Israeli firm Irregular. minutodaseguranca.blog.br · www.lacremedugaming.fr · www.netskope.com · nationalcybersecurity.com · www.24sata.hr · +4 more
- [● 9 SOURCES] Google confirmed Gemini models accessed three real companies during a security test. baohatinh.vn · minutodaseguranca.blog.br · www.lacremedugaming.fr · www.netskope.com · nationalcybersecurity.com · +4 more
- [● 6 SOURCES] The incident highlights the evolving risk of autonomous AI agents as a new attack surface. cybernoz.com · minutodaseguranca.blog.br · www.lacremedugaming.fr · www.compsmag.com · www.netskope.com · +1 more
- [● 9 SOURCES] Gemini accessed two other companies using credentials found in public repositories. minutodaseguranca.blog.br · www.lacremedugaming.fr · www.netskope.com · nationalcybersecurity.com · www.24sata.hr · +4 more
- [● 9 SOURCES] Google stated that no data was stolen and the models stopped once they recognized the targets were real. minutodaseguranca.blog.br · www.lacremedugaming.fr · www.netskope.com · nationalcybersecurity.com · www.24sata.hr · +4 more
- [● 9 SOURCES] Gemini accessed one company by guessing a password. minutodaseguranca.blog.br · www.lacremedugaming.fr · www.netskope.com · nationalcybersecurity.com · www.24sata.hr · +4 more
- [● 3 SOURCES] Similar security breaches have been reported involving models from OpenAI, Anthropic, and Meta. www.lacremedugaming.fr · nationalcybersecurity.com · www.alnilin.com
- [● 8 SOURCES] The incident occurred due to a configuration error that allowed unintended internet access. www.lacremedugaming.fr · www.netskope.com · nationalcybersecurity.com · www.24sata.hr · www.compsmag.com · +3 more