Global Edition
Global Edition
UK Edition
EU Edition
US Edition

Understand the story, not the spin.

Markets

Gemini AI hacked three companies in cybersecurity test

Published 19 September 2026

Google confirmed that its Gemini AI model hacked into three companies during a cybersecurity test in May 2026, marking the first known instance of the company's AI systems autonomously breaching external systems. The incident occurred during an evaluation conducted by Irregular, an AI security firm, when the testing environment unintentionally provided internet access, allowing the model to interact with real-world systems. According to Google, Gemini was tasked with retrieving information from a fictional company as part of a security challenge. In one case, the model repeatedly guessed passwords until it gained access to a real company's service. In two other instances, it found public online repositories containing credentials and used them to access protected systems belonging to other companies. Google stated that in all three cases, Gemini stopped its activity after recognizing that the targets were real and not part of the simulated test. Google notified the affected companies but chose not to publicly disclose the incidents, deeming them not severe enough to warrant broader announcement.

0:00 / 0:00