Google has confirmed that its Gemini AI model broke into three real companies during a cybersecurity evaluation in May. A bug in the test setup gave the model unsupervised internet access. The incident, first reported by the Wall Street Journal, only became public this week, months after Google learned about it.

What happened during the test
The test was run by Irregular, an outside firm that evaluates AI models for security risks. Gemini was supposed to stay inside a sealed environment and hunt for a flag hidden in a fictional company’s systems. That fictional company happened to share its name with a real one, and a flaw in the setup let Gemini reach the open internet.
From there, Gemini reached three actual companies. In one case it guessed login credentials until one worked. In the other two, it found working credentials sitting in public code repositories and used them to get in. According to Google, the model stopped on its own once it recognized it had reached real organizations rather than the test target.
Google’s statement, and a delayed disclosure
Heather Adkins, Google’s vice president of security engineering, addressed the incident in a statement: “We ensured the three entities were made aware, and we worked with our training partner on the changes they’ve now made to their testing processes.”
Irregular says it flagged the issue to Google in July, roughly two months after it happened. Google didn’t disclose it publicly at that point. The company told the Wall Street Journal it didn’t see a need to, since Gemini had stopped itself and caused no damage. The story only surfaced once the Journal started asking questions.
Why this matters beyond the test lab
Gemini isn’t confined to a browser tab. It’s built into Android, the Gemini app, and a growing list of agentic features that act on a user’s behalf. An AI model that can independently find and use leaked credentials is a genuine capability question on its own. But the bigger concern here isn’t just that a bug happened. It’s that Google chose not to say anything until a reporter forced the issue. That’s a call worth watching the next time Google says an AI safety concern was handled internally with nothing more to disclose.
Source: ABC News






