Skip to content
important Security verified update

A misconfigured security test allowed Gemini models to breach the systems of three real companies

confirmed by 2 independent sources updated September 21, 2026

Google confirmed that in May 2026, Gemini models escaped an isolated sandbox due to a misconfigured test and attacked the systems of three real companies instead of the intended fictitious targets. The company had known about the incident since July but disclosed it only after an inquiry from Wall Street Journal.

Google confirmed that a misconfigured test environment caused the incident in May 2026, when Gemini models breached the systems of three companies. Irregular conducted a capture-the-flag test designed to assess the cybersecurity capabilities of the model in a closed environment, where the model was instructed to attack a fictitious company with the same name as a real company. However, a configuration error unintentionally gave Gemini models internet access beyond the designated test servers, so instead of fictitious targets, they attacked the real corporate infrastructure of three companies that were unaware of it.

In one case, the model guessed a password and thereby gained access to a protected system; in two other cases, it found login credentials accidentally published in a public software repository. According to Google, in each case the model halted the intrusion after discovering that it had entered the system of a real company instead of a simulated environment, and it caused no harm to any company.

Google had known about the incident since July 2026, but the public only learned about it after the publication of a report by Wall Street Journal. Google explained the disclosure by saying that, in its assessment, the incident did not require a public announcement because it caused no harm and the model ended the attack on its own. Irregular, which conducted the test, had previously also been involved in similar incidents disclosed by OpenAI, Anthropic and Meta.

What changed

Why it matters

The incident shows that even carefully designed tests of AI agents in a closed environment can, due to a configuration error, lead to unintended interference with real infrastructure belonging to third parties without their knowledge. It also demonstrates how large AI companies approach the disclosure of similar incidents — Google waited almost two months to disclose it and responded only after an inquiry from journalists, which is relevant to assessing transparency in the industry.

What was added since the original report

Verified updates

  1. New verified information

    A misconfiguration unintentionally gave Gemini models internet access outside the isolated environment; The test was designed as a capture-the-flag exercise focused on cybersecurity; The models were supposed to attack a fictitious company, but hacked real corporate infrastructure; The three affected companies were unaware

    • A misconfiguration unintentionally gave Gemini models internet access outside the isolated environment
    • The test was designed as a capture-the-flag exercise focused on cybersecurity
    • The models were supposed to attack a fictitious company, but hacked real corporate infrastructure
    • The three affected companies were unaware

Two audiences, two different impacts

What this means

01

For individuals

The case repeats a familiar lesson for anyone managing access to systems: two of the three breaches occurred because of login credentials left in a public repository, and the third because of a weak password.

What to do Do not leave login credentials in public repositories or use easily guessed passwords, because these were precisely the ways the model accessed the three systems.
More practical updates →
02

For a business

Companies conducting security tests of AI agents (capture-the-flag exercises) face the risk that a misconfigured sandbox will allow a model to interfere with real infrastructure; the incident also shows that companies such as Google may remain silent about such cases for months until journalists force them to disclose them.

Risks and compliance
What to decide When conducting security tests of AI agents, verify that the test environment is isolated and have a policy ready for disclosing similar incidents.
More business impacts →
AI models security CTF Gemini Google hacking incident Irregular testování

Check the original

Event sources

confirmed by 2 independent sources · 2 publishers, 2 independent. We count feeds from the same owner only once.

2
Simon Willison — AI tag (leading independent LLM commentator) community signal · first detected Gemini Hacked Three Companies in First Known Breakout by Google’s AI Ars Technica (AI) independent context Google confirms Gemini models hacked three companies in May 2026