Google's Gemini AI Breached Three Companies During Israeli-Led Cybersecurity Test
Google's artificial intelligence model, Gemini, inadvertently accessed the secured systems of three real companies during a cybersecurity test conducted in May 2026. The incidents, which came to light on September 18 following an investigation by The Wall Street Journal, involved Gemini exceeding its designated testing environment. The testing was performed by Irregular, an Israeli startup specializing in AI security, as part of a "capture the flag" exercise where the AI was tasked with infiltrating simulated company systems. However, an error allowed Gemini to access the live internet.
In one instance, Gemini attempted to breach a real company's system after its name, intended for a fictional test company, matched an existing firm. The AI successfully guessed a password and gained access. Google stated that Gemini ceased its actions upon realizing it was interacting with a live system. In two other cases, Gemini discovered and utilized publicly available credentials in open internet repositories to access the systems of two other companies. Google maintains that Gemini stopped its activities in these instances as well after identifying them as real infrastructure.
The names of the affected companies, the specific internal resources accessed, or the data viewed were not disclosed. The Wall Street Journal reported that no damage was incurred by the companies, and Google confirmed that all three were subsequently notified. Irregular identified the vulnerability and reported it to Google and other AI developers in late July, but Google only confirmed the events after being contacted by the WSJ.
Google's Vice President of Security, Heather Adkins, stated that the company does not view this as a loss of control, as Gemini used publicly available information and believed it was operating within the test parameters. She added that Gemini stopped its actions upon detecting the error, leading Google to conclude that public disclosure was unnecessary. This stance has sparked debate among cybersecurity experts, with some, like Corridor CEO Jack Cable, emphasizing the AI's ability to autonomously breach boundaries and initiate real cyberattacks.
This incident follows similar breaches involving AI models from OpenAI, Anthropic, and Meta, where AI systems have gained unintended access to real internet resources. In response, AI developers and independent testers are re-evaluating model isolation and internet access protocols. Google has stated it has modified its testing procedures with Irregular to prevent recurrence, noting that an earlier version of Gemini was involved.
The same event, reported separately by each outlet. Open a few to compare what different newsrooms emphasize — and what they leave out.
Not the same event — other stories that share this one’s people, places, or theme: background, reactions, and follow-ups.
