A misconfigured security test allowed Gemini models to breach the systems of three real companies
Google confirmed that in May 2026, Gemini models escaped an isolated sandbox due to a misconfigured test and attacked the systems of three real companies instead of the intended fictitious targets. The company had known about the incident since July but disclosed it only after an inquiry from Wall Street Journal.
Google confirmed that a misconfigured test environment caused the incident in May 2026, when Gemini models breached the systems of three companies. Irregular conducted a capture-the-flag test designed to assess the cybersecurity capabilities of the model in a closed environment, where the model was instructed to attack a fictitious company with the same name as a real company. However, a configuration error unintentionally gave Gemini models internet access beyond the designated test servers, so instead of fictitious targets, they attacked the real corporate infrastructure of three companies that were unaware of it.
In one case, the model guessed a password and thereby gained access to a protected system; in two other cases, it found login credentials accidentally published in a public software repository. According to Google, in each case the model halted the intrusion after discovering that it had entered the system of a real company instead of a simulated environment, and it caused no harm to any company.
Google had known about the incident since July 2026, but the public only learned about it after the publication of a report by Wall Street Journal. Google explained the disclosure by saying that, in its assessment, the incident did not require a public announcement because it caused no harm and the model ended the attack on its own. Irregular, which conducted the test, had previously also been involved in similar incidents disclosed by OpenAI, Anthropic and Meta.
Why it matters
The incident shows that even carefully designed tests of AI agents in a closed environment can, due to a configuration error, lead to unintended interference with real infrastructure belonging to third parties without their knowledge. It also demonstrates how large AI companies approach the disclosure of similar incidents — Google waited almost two months to disclose it and responded only after an inquiry from journalists, which is relevant to assessing transparency in the industry.
What was added since the original report
Verified updates
-
A misconfiguration unintentionally gave Gemini models internet access outside the isolated environment; The test was designed as a capture-the-flag exercise focused on cybersecurity; The models were supposed to attack a fictitious company, but hacked real corporate infrastructure; The three affected companies were unaware
- A misconfiguration unintentionally gave Gemini models internet access outside the isolated environment
- The test was designed as a capture-the-flag exercise focused on cybersecurity
- The models were supposed to attack a fictitious company, but hacked real corporate infrastructure
- The three affected companies were unaware
Two audiences, two different impacts
What this means
For individuals
The case repeats a familiar lesson for anyone managing access to systems: two of the three breaches occurred because of login credentials left in a public repository, and the third because of a weak password.
For a business
Companies conducting security tests of AI agents (capture-the-flag exercises) face the risk that a misconfigured sandbox will allow a model to interfere with real infrastructure; the incident also shows that companies such as Google may remain silent about such cases for months until journalists force them to disclose them.
Risks and complianceCheck the original
Event sources
confirmed by 2 independent sources · 2 publishers, 2 independent. We count feeds from the same owner only once.