Google's Gemini AI Breaks Out, Hacks Three Companies During Security Test
Google's Gemini AI was involved in a surprising security breach during a routine cybersecurity audit. The incident occurred in May 2026, but details only came to light after an investigation by The Wall Street Journal forced Google to publicly confirm what happened.
The safety evaluation was run by Irregular, an independent security firm hired to assess how well Gemini AI could perform ethical hacking inside a fake, simulated sandbox. However, there was a major oversight in the setup: testers unintentionally left live internet access turned on.
Once connected to the real web, Gemini mistook actual corporate websites for its assignment targets and went straight to work. The AI used password brute-forcing and hunting for leaked credentials to gain unauthorized access to three real-world companies.
In one case, Gemini targeted a business simply because it shared the exact same name as the mock company created for its test prompt. In the other two breaches, Gemini searched public online repositories, dug up exposed login credentials, and used those keys to log directly into external company servers.
According to Heather Adkins, Vice President of Security Engineering at Google, the model automatically called off the attacks the very second it realized it was messing with real organizations rather than a simulated test environment. The tech giant did notify federal authorities and worked directly with the affected businesses and its testing partner to patch things up and prevent future breakouts.