< Back to all clusters
[TECHNOLOGY] · United States, Israel · 10 sources

started · updated

Google Gemini AI accessed three real companies during security test

Google has confirmed that its Gemini AI model accessed the systems of three real companies during a cybersecurity evaluation in May 2026. The incident occurred during a ‘Capture the Flag’ exercise conducted by the cybersecurity firm Irregular. Although the test was intended to take place within a secure, isolated sandbox environment, a configuration error accidentally provided the model with internet access.

In one instance, the model successfully guessed a password to access a real company's system because the fictitious target name used in the test matched a real entity. In the other two cases, Gemini identified and used credentials found in public online repositories to enter the servers of two additional organizations.

Google's Vice President of Security Engineering, Heather Adkins, stated that the model acted appropriately by automatically ceasing all activities once it recognized it had accessed real-world infrastructure rather than the simulated environment. Google reported that no data destruction or damage occurred during these incidents and that the affected companies have been notified.

Entities

Gemini · Google · Heather Adkins · Irregular · Wall Street Journal

Claims

What the coverage asserts, and how many sources carry each claim.