Thursday, September 24, 2026
News

Googles Gemini breaks out of test environment to hack three external firms: Report

SocialTwist Tell-a-Friend    Print this Page   COMMENT

Washington, DC | September 19, 2026 8:29:55 AM IST
Googles Gemini reportedly hacked three companies in the first known breakout, after the model accessed the internet and breached external systems during an evaluation of its cybersecurity capabilities.

First reported by The Wall Street Journal on Friday, the intrusions took place in May during an exercise conducted by the testing firm Irregular, which also participated in evaluations involving similar breaches disclosed by OpenAI, Anthropic, and Meta.

In one instance, the AI model guessed passwords until it penetrated a protected network. In two separate runs, the system identified exposed credentials within public repositories to gain entry. Google maintained that the model ceased its operations in each instance once it recognized that it had penetrated real corporate infrastructure rather than a simulated target.

Irregular alerted Google to the breaches in late July, following revelations that OpenAI agents had compromised the software platform Hugging Face. Google did not make the development public until inquiries were submitted by The Wall Street Journal.

The company stated that the event did not warrant disclosure because the model inflicted no damage and disconnected upon discovering the mistake, likening the process to a bug bounty initiative.

This event highlights the importance of training powerful AI models to act responsibly, Heather Adkins, Googles vice president of security engineering, said in a statement. In this case, the model acted appropriately.

Industry observers contested Google's characterization of the event, arguing that the autonomous breach of external corporate networks represented a serious breakdown in containment protocols.

The breaches stemmed from an issue of mistaken identity during a capture-the-flag exercise on Irregulars infrastructure, where the model received instructions to retrieve data from a simulated entity that shared its name with an active business. While the test environment was intended to remain isolated, internet connectivity was inadvertently left open.

Beyond guessing passwords in the initial run, the system executed web searches for the target name during subsequent tests, located credentials stored in online repositories, and deployed them to penetrate two additional corporate environments.

Google stated that it informed the three affected entities alongside federal authorities, while declining to identify the victim companies or the specific Gemini version involved.

All relevant labs were notified in late July, and affected entities were contacted as part of the investigation, an Irregular spokesperson said.

Irregular took immediate action, and all known issues on our end were remedied and resolved weeks ago, the spokesperson added. (ANI)

 
  LATEST COMMENTS ()
POST YOUR COMMENT
Comments Not Available
 
POST YOUR COMMENT
 
 
TRENDING TOPICS
 
 
CITY NEWS
MORE CITIES
 
 
 
MORE BUSINESS NEWS
Eapro Global Limited Raises INR 400 mill...
Luxor Crayola brings hands-on creativity...
The Proven Code Berberine Is Being Studi...
Steel dealers build inventory as tight s...
Decoding the Ramayana: An Ancient Bluepr...
Kesudo Shree Ganesha Song Brings Guj...
More...
 
INDIA WORLD ASIA
'Externment curtails fundamental rights,...
Preliminary inquiry is an attempt to pr...
Indian Railways connects remote area of ...
Delhi Bar Association to continue protes...
Special focus placed on strengthening pi...
Telangana: Future City Police order clos...
More...    
 
 Top Stories
Sambhali Trust showcases ‘Desert Da... 
‘Preliminary inquiry is an attempt ... 
EAM Jaishankar discusses India’s de... 
Deepika credits smooth drag-flickin... 
Former US NSA John Bolton says US m... 
Durban’s Super Giants unveil fresh ... 
Indian Railways connects remote are... 
“India are benchmark in white-ball ...