You too Google! Google Confirms Gemini Breached 3 Companies in AI Security Tests
Google confirmed on Friday, September 18, 2026 that a Gemini model accessed 3 outside companies’ systems. The Wall Street Journal first reported the incidents, which happened in May. The breaches happened during a capture-the-flag exercise run by Irregular, a third-party AI security evaluator. Per Axios , Gemini was asked to retrieve information from a fictional company. That fictional company shared its name with a real one. The test was never supposed to touch the internet. CNBC reports that a bug in the testing environment made internet access available. The techniques were basic. In 1 case, Gemini guessed passwords until it got in. In the other 2, it used credentials found in a public repository. Google says the model stopped each time once it realized the systems belonged to real companies. Heather Adkins, Google’s VP of security engineering, said in a statement reported by CNN that the 3 entities were made aware, and that Google worked with its trai...
