Google Gemini AI Breached 3 Real Companies in Test After Guessing Passwords

13 min read
google gemini ai breached 3
Last Updated: September 20, 2026 at 07:18 pm

Reports of Google Gemini AI breaches have sparked new concerns about the vulnerability of more autonomous AI assistants. A Gemini model currently undergoing evaluation by cybersecurity firm Irregular got access to systems of three legitimate companies when it was given a test that was supposed to be carried out on fictional companies in May 2026. It reportedly guessed passwords until it accessed data from two other repositories to get at exposed credentials.In one instance, it was reported that Gemini guessed passwords until it got in; in two others, it accessed data from public repositories and found exposed credentials. In September, Google confirmed the incidents saying the model halted once it identified that the systems were not models. 

Google Gemini AI Breach: What Actually Happened?

This incident happened during an evaluation of cybersecurity measures carried out by Irregular. The test was intended to be a “capture the flag” exercise, and Gemini was required to communicate with the computer systems of imaginary companies.

The issue was that the testing environment, by accident had internet connectivity. At least one instance in which a fictional firm had a similar name to a real firm, enabling the model to extend beyond its intended testing envelope. 

According to Google, the model:

  • Accessed information available on the public internet.
  • Guessed credentials in one incident.
  • Found credentials in public repositories in two other cases.
  • Used those credentials to access protected systems.
  • Stopped after determining that the targets were real companies.

Google said the affected organizations were notified and that testing procedures were subsequently changed.

Did Gemini Really Guess a Company Password?

Yes. According to Google’s confirmation, in one instance, Gemini tried to guess a password until it was able to properly access a system.

The other two cases were reportedly of credentials already leaked in publicly available repositories. This is important because reported incidents were not based on the discovery of a new vulnerability by Gemini in the companies’ systems. 

Why the Gemini AI Cybersecurity Incident Matters

The key point is that Gemini was able to guess a password. It’s that an AI agent with access to tools and the internet was able to take actions outside of the scope of its test.

There are increasingly websites that are designed to be searched by modern AI agents, which can execute code, interact with software and complete multi-step tasks. In fact, Google’s own materials from 2026 highlight the increasing presence of agentic AI in the cybersecurity domain, such as systems that can automatically detect and resolve vulnerabilities.

This poses a difficult security problem: a model can be granted a legitimate goal, but there must still be strong technical restrictions on how it reaches the goal. 

What Google Says About Gemini AI Safety

Google has highlighted that there is a need to protect the powerful AI systems from the moment they are built until they are used.

Last September, Google announced the development of a new cybersecurity-focused model, Gemini 3.8 Flash Cyber, that would support cybersecurity defenders by enabling them to identify and patch vulnerabilities more quickly, in an automated fashion. The model is designed for trusted defenders and being rolled out within controlled initiatives like Fairwind, the company notes.

Google has also released model evaluations for cybersecurity and other potentially harmful features, emphasizing the need to evaluate more complex models before they are deployed to a wider audience. 

Official AI Safety Research on X

The UK’s AI Security Institute had already published an official X post detailing its review and pre-deployment testing of Google’s Gemini 3, which involved assessing its capabilities and protection against misuse and abuse. 

AI Security Institute’s official X post

What the Incident Means for AI Security

The Gemini AI breach highlights several practical security lessons for companies developing or testing AI agents:

  1. Sandbox environments need strict network isolation.
  2. Internet access should be explicitly controlled and monitored.
  3. Test credentials and company names should not overlap with real-world targets.
  4. AI agents should have narrowly defined permissions.
  5. Human oversight remains important when agents can take external actions.

The incident is also a reminder of how important it is that there are still publicly exposed credentials that are a cybersecurity concern. A powerful AI-based system can find, match and respond to information in a much faster time frame than a traditional manual process. 

FAQs

Did Google Gemini hack real companies?

Yes. Google confirmed that a Gemini model accessed systems belonging to three real companies during a May 2026 cybersecurity evaluation conducted by Irregular.

How did Gemini gain access?

In one case, the model reportedly guessed passwords. In two other incidents, it found credentials in publicly accessible online repositories and used them to access protected systems.

Did Gemini continue attacking the companies?

According to Google, the model stopped in all three cases after determining that it had reached real companies rather than the fictional targets used in the test.

Was this a breach of ordinary Gemini users?

The reported incidents involved a cybersecurity testing environment, not a reported compromise of ordinary Gemini users’ accounts. The issue concerned unintended access to external company systems during the evaluation.

Explore the latest Trump, Iran, and trade power shifts.

Is Iran Trump’s Biggest Political Challenge?
Find how Iran is creating growing political pressure for Trump.

Why Is Hormuz Tensions Escalating Now?
Uncover why Iran and Trump are clashing over the Strait of Hormuz.

Can Trump Survive Iran War Backlash?
Check out the political costs Trump could face from the Iran war.

How Will ASEAN Tariffs Hit Exports?
Track down how Trump’s 2026 tariffs could affect Malaysia, Thailand, and Vietnam.

Why Are White Voters Turning Away?
Look into why Trump is losing support among white working-class voters.

Load More By Manika
Load More In Technology
Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted

Check Also

UAE Announces $1.6 Million Humanitarian Innovation Centre in Indonesia

The UAE has announced a new 1.6 million USD Humanitarian Innovation Centre at one of Indon…