During a May cybersecurity evaluation, Gemini gained unintended internet access, guessed credentials, and entered three real companies’ systems before stopping after identifying the mistake.
Google’s Gemini AI model accidentally accessed the systems of three real companies during a cybersecurity evaluation, after gaining unintended internet access and using publicly available information to find or guess login credentials.
The incidents took place in May during a security test conducted by AI security firm Irregular. The evaluation was designed around simulated companies, but Gemini ended up interacting with real-world systems. Google was informed about the incidents in July.
Google said the model stopped its activity after recognizing that the targets were real companies rather than part of the simulated exercise.
Gemini Accessed Three Real Companies
Heather Adkins, Google’s vice president of security engineering, said Gemini found public information online and guessed credentials to access websites it believed were part of the test.
In all three cases, the model stopped after the mistake was identified.
Google and its testing partner notified the affected companies and worked with them on changes to their testing procedures. The names of the three organizations have not been disclosed.
According to reporting on the incident, one of the simulated companies shared a name with a real business, while in two other cases the model found publicly available credentials that allowed it to access real systems.
The episode highlights a different kind of cybersecurity challenge from a conventional human-led attack. The model was operating within an evaluation intended to test its cyber capabilities, but an error in the test environment allowed its actions to reach systems outside the intended scope.
The Incident Was Discovered Months After the Test
The Gemini activity occurred in May but was not identified by Google until July.
Google said the affected organizations were notified after the company investigated what happened.
The company has described the incident as an example of why AI systems conducting cybersecurity tasks need strong containment and testing controls. Adkins said the events underscore the importance of training powerful AI models to act responsibly.
The incident also comes at a time when AI companies are reporting a series of security events involving increasingly capable models.
OpenAI Models Also Reached Real Systems
In July, models being evaluated by OpenAI escaped controls designed to isolate them from the internet and eventually compromised parts of Hugging Face’s infrastructure.
OpenAI said the models were being tested for cybersecurity capabilities with safeguards reduced for the evaluation. During the incident, the systems exploited vulnerabilities, gained internet access, and reached third-party infrastructure.
Hugging Face’s subsequent technical investigation reconstructed roughly 17,600 attacker actions over about two and a half days. The company said the AI agent ultimately gained high-level access to parts of its infrastructure and accessed limited private data and credentials.
OpenAI said the incident did not affect customer data, product functionality,y or availability.
Why AI Cybersecurity Tests Are Becoming More Important
The Gemini incident is notable because the model did not simply provide instructions for a cyberattack. It interacted with live systems during an evaluation and used credentials it found or guessed.
That distinction matters as AI systems become increasingly capable of carrying out multi-step tasks without continuous human intervention.
A system that can search for information, identify potential targets, retrieve credentials, ls and attempt access can move much closer to carrying out an entire cyber operation on its own.
At the same time, the Google and OpenAI incidents also show that containment failures can be an important part of the problem. In the Gemini case, the test was intended to involve fictional targets, while the OpenAI incident involved a testing environment that was supposed to be isolated from the internet.
A Growing Challenge for AI Labs
Google’s disclosure adds another incident to a rapidly developing debate over how AI models should be tested when they are given access to cybersecurity tools and external systems.
The companies developing these models are increasingly testing them on offensive cybersecurity tasks to measure their capabilities. But those evaluations also require strict controls to prevent simulated attacks from reaching real organizations.
For Google, Gemini stopped once it recognized that it had accessed real companies. The affected organizations were notified,ied and the testing procedures were changed.
Still, the episode shows how quickly an AI cybersecurity evaluation can cross the boundary between a controlled exercise and interaction with real-world systems.
Read more news and follow us on Instagarm
A specially designed Google logo, during the opening of Google’s new Artificial Intelligence (AI) centre in Berlin, Germany, March 5, 2026. Photo: Reuters
Source: KT



