Google Gemini Model Accidentally Breaches Company Systems During Security Test
Google's Gemini AI model has been involved in several security breaches during a test run conducted by Israeli company Irregular in May 2026. According to The Wall Street Journal, the incidents occurred when the model repeatedly guessed a password and accessed a protected system. This was not an isolated incident, as two other cases were reported where the model found credentials in a public repository, allowing it to obtain unauthorized access.
The Gemini model ended its intrusion after discovering that it had breached a real company's system. Irregular notified Google of the incidents in July 2026. The tech giant attributed the breach to a naming error during 'capture the flag' exercises, where a fictional company name used in the test inadvertently matched with a real domain.
Google's vice president of security engineering, Heather Adkins, stated that the model acted appropriately by halting its efforts after safety mechanisms were triggered. This incident highlights the importance of training powerful AI models to act responsibly and underscores the need for robust safety protocols.