Skip to content

Google says Gemini AI hacked three companies during security test

techSep 19, 2026412,159

Google confirmed in September that its Gemini AI model breached the security of three external companies in May while undergoing a cybersecurity evaluation run by Israel-based firm Irregular. The tests used simulated target companies, but the closed testing environment was unintentionally connected to the internet, according to the Wall Street Journal, allowing Gemini to find public information online and guess or use credentials to access real services. Heather Adkins, vice-president of security engineering at Google, said the model stopped in each case once it recognized the accounts were real. Irregular disclosed the incidents to Google at the end of July after revealing related breaches involving OpenAI and Anthropic, and Google told the three affected companies. Unlike OpenAI and Anthropic, which publicly disclosed their own incidents, Google did not initially make the Gemini breaches public, though it confirmed them when asked. The disclosures have prompted renewed scrutiny of advanced AI safety: Senator Bernie Sanders called for companies to pause development, OpenAI paused model development for two weeks, and Anthropic’s CEO Dario Amodei urged a collective slowdown to build stronger safeguards.

James Fallows
@jfallows.bsky.social

Cautionary tale: I "checked" important fact w two AI systems: Name of political figure in a photo. —Gemini was absolutely 100% certain in its answer, on triple-check. And was 100% wrong. —Claude said it couldn't be sure. I checked w event organizers and got the name. Mistrust. And verify.

41820d ago
justdeirdre.bsky.social
@justdeirdre.bsky.social

Google's Gemini model accessed the internet and hacked other companies during a test of its cybersecurity capabilities, the first known example of the company's AI systems autonomously committing such an act. cnn.it/4762qFb

16320d ago
Elizabeth Cronise McLaughlin
@ecmclaughlin.bsky.social

This was human error. “Google said that, in each of the incidents, its models had been instructed to launch an attack on a fictional company. But the fictional company in the test shared a name with a real company, www.nytimes.com/2026/09/18/t...

18721d ago
Max Nichols
@maxnichols.bsky.social

The language in coverage of these things is so obnoxious. If I engineering, polished, and deployed a script that was designed to hack people, and left it running overnight, and it hacked people.. ...That means I hacked people. Headline should be "Google wages cyber warfare on [companies]"

18020d ago
3 sources