Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Who are the 100 world-leading environmentalists, according to The Independent? – Press Review

    September 21, 2026

    Ed Davey rejects claims party is ‘sleepwalking into irrelevance’ under his leadership – UK politics live | Politics

    September 21, 2026

    TechCrunch Mobility: How do we know when an AV is safe enough?

    September 21, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Who are the 100 world-leading environmentalists, according to The Independent? – Press Review
    • Ed Davey rejects claims party is ‘sleepwalking into irrelevance’ under his leadership – UK politics live | Politics
    • TechCrunch Mobility: How do we know when an AV is safe enough?
    • How to Improve Visibility Across Your Enterprise AI Ecosystem
    • 5 ways AI is reshaping the cybersecurity job market
    • Bitcoin: $80K rebound faces inflation-expectations test
    • New study reveals the genetic history – and possible future
    • All the signs say another financial crisis is coming. Here’s why we need to prepare for it now | Larry Elliott
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, September 21
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Google Confirms Gemini AI Breached Three Firms

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 21, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Google has confirmed that one of its Gemini models accessed the systems of three real companies during a cybersecurity test in May. 

    The Wall Street Journal first reported the incidents on Friday, describing them as the first known case of Google’s AI systems autonomously hacking other companies.

    The test was run by Irregular, the AI testing company that was also involved in incidents disclosed by Meta, OpenAI and Anthropic. Heather Adkins, Google’s VP of security engineering, gave SecurityWeek the following statement about the Gemini incidents:

    “Safe development of powerful AI models is critical and we invest deeply in this area. In a standard evaluation, the model found public information online and guessed credentials to access websites it thought were part of the test. In all three of these instances, the model stopped.”

    Google described the incidents to the WSJ as mistaken identity. Gemini was taking part in a capture-the-flag exercise on Irregular’s infrastructure, tasked with retrieving information from software run by a fictional company that shared its name with a real one.

    The model was not intended to have internet access, but Irregular said access was unintentionally made available. In one case, the model guessed passwords until it gained access to a protected system. In two other runs, it searched the web using the company’s name, found credentials belonging to other companies in public repositories and used them to access the associated systems.

    Google said the model realized in each case that it had reached a real company and ended the intrusion. Irregular notified Google at the end of July. Unlike the other AI companies involved in similar incidents, Google did not disclose the findings until it was contacted by the WSJ.

    Advertisement. Scroll to continue reading.

    According to Google, the incidents did not warrant public disclosure because the model caused no harm and stopped immediately. It also said they were not an instance of model misalignment, since its safety measures helped the model stop. The company compared the episode to a bug bounty program.

    Google told the WSJ it notified federal authorities and the three affected companies, whose names it did not share. Adkins added the following in her statement to SecurityWeek:

    “Our security team has a long track record of reporting issues we find in other people’s software and systems – even if it’s as simple as a weak password. We ensured the three entities were made aware, and we worked with our training partner on the changes they’ve now made to their testing processes. These events highlight the importance of training powerful AI models to act responsibly.”

    Google said the incident did not involve its latest model, but did not disclose the model’s name. 

    Irregular noted that Google’s case was the same as the other incidents and does not represent a new problem. A spokesperson said all known issues on its end were fixed weeks ago.

    AI companies taking action in response to incidents

    Since their initial disclosures, OpenAI and Anthropic have discovered several additional incidents in which their models hacked real companies or exhibited misaligned behavior. 

    OpenAI agents were linked to a RubyGems attack earlier this year. In addition, the company disclosed six misalignment incidents last week, including agents searching GitHub for leaked API keys, unsanctioned collaboration between agents, moving data outside the intended environment, using jailbreak-style instructions for manipulation, and attempts to conceal failures.

    Anthropic has expanded the scope of its search for incidents involving unauthorized access to real systems, which led to the discovery of a new breach. 

    Both OpenAI and Anthropic have announced taking action in response to these incidents. Anthropic paused evaluations and rolled out new protections against test environment escapes. It has also developed an enterprise system that combines zero data retention with automated misuse monitoring. 

    OpenAI has proposed a framework to speed up publication of misalignment findings, and it has overhauled model security. The company is also leading a cyber defense pledge and is offering subsidized AI cyber capabilities to critical infrastructure defenders.  

    The AI testing company Irregular has also detailed the action it took in response to incidents in which real systems were hacked during its evaluations. 

    Related: AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code 

    Related: Beijing Hits Back at Anthropic CEO’s Call to Curb China’s AI Development

    Related: Anthropic Researcher Resigns With Warning About the Dangers of AI Development

    breached Confirms firms Gemini Google
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    5 ways AI is reshaping the cybersecurity job market

    Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors

    You too Google! Google Confirms Gemini Breached 3 Companies in AI Security Tests

    The Guardian view on AI v mathematicians: humans are still vital to the field, but tech firms refuse to see that | Editorial

    Malicious npm packages evade install-script defenses at runtime

    Researchers escape OpenAI Codex sandbox to run commands on host

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Who are the 100 world-leading environmentalists, according to The Independent? – Press Review

    September 21, 2026

    Ed Davey rejects claims party is ‘sleepwalking into irrelevance’ under his leadership – UK politics live | Politics

    September 21, 2026

    TechCrunch Mobility: How do we know when an AV is safe enough?

    September 21, 2026

    How to Improve Visibility Across Your Enterprise AI Ecosystem

    September 21, 2026
    Latest Posts

    Primary Elections Live Updates: Race Too Close to Call in Democratic Primary for Michigan Senate Seat

    August 5, 2026

    Europe has the defense budget. The test now is delivery. – POLITICO

    August 5, 2026

    As Spain grieves, recurrent heatwaves stir fears of more wildfires | Weather News

    August 5, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Who are the 100 world-leading environmentalists, according to The Independent? – Press Review

    September 21, 2026

    Ed Davey rejects claims party is ‘sleepwalking into irrelevance’ under his leadership – UK politics live | Politics

    September 21, 2026

    TechCrunch Mobility: How do we know when an AV is safe enough?

    September 21, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.