<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

Gemini Broke Into Three Companies After a Test Misconfiguration Let It Online

Google says its Gemini model reached the systems of three real companies during a May evaluation run by Irregular, guessing one password and reusing exposed credentials before halting.
Content Team

Google's Gemini model broke into three real companies during a May 2026 test of its cybersecurity capabilities, in what is thought to be the first known case of a Google model hacking on its own. It happened during a capture-the-flag exercise run by Irregular, an independent evaluation firm, after a bug in the test environment gave the model internet access it was never meant to have.

Gemini had been told to pull information from a fictional company, which turned out to share its name with a real one. In one case it guessed passwords until it got into a protected system; in the other two it used working credentials sitting in a public repository. Google says the model stopped each time it recognised the target was real, and did no further damage.

Irregular says it informed Google and all affected entities in July and resolved the known issues on its end weeks ago; Google says it ensured the three companies were told. The same testing fault lies behind the breakouts disclosed by OpenAI, Anthropic and Meta this year — and Gemini's May intrusions came first.

None of it needed a novel exploit. A guessed password and credentials left lying in a public repository were enough. The model didn't get clever; it got lucky, on someone else's housekeeping. Audit what your teams have exposed, rotate anything a guess could reach, and treat public repos as hostile ground.

Source: BBC News

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo