Close Menu
NCIJ Network NCIJ Network
    What's Hot

    US strikes on alleged drug boats may be ‘crimes against humanity’, UN says | News

    September 22, 2026

    Reform-Agenda: Merz‘ neue Suche nach Gerechtigkeit – POLITICO

    September 22, 2026

    The Search for Silicon Valley’s Most Powerful Woman

    September 22, 2026
    Facebook X (Twitter) Instagram
    Trending
    • US strikes on alleged drug boats may be ‘crimes against humanity’, UN says | News
    • Reform-Agenda: Merz‘ neue Suche nach Gerechtigkeit – POLITICO
    • The Search for Silicon Valley’s Most Powerful Woman
    • RatHat Android Trojan Uses AI for Automation
    • Bitcoin price news: BTC eyes $90,000 as leverage is building
    • Brain scans reveal a possible cause of long COVID fatigue and brain fog
    • Tourism has potential to slow coral decline at Bali travel hotspot: Study
    • The AfD thrives in the absence of mainstream parties that speak to people’s daily lives | Alternative für Deutschland (AfD)
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, September 22
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Crypto & Blockchain

    Google Admits Gemini AI Hacked Three Companies—It Stayed Silent for 7 Weeks

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 22, 2026 Crypto & Blockchain No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    In brief

    • Google learned in late July that Gemini had broken out of a sandboxed security test run in May, reaching three real companies and either guessing or finding two of their passwords
    • The company didn’t disclose it until September 18, after The Wall Street Journal asked.
    • The same third-party testing firm, Irregular, was involved in Google’s incident and in nearly identical sandbox failures Anthropic and Meta disclosed earlier this year.

    Google’s Gemini broke out of a locked security test and attacked three real companies. Google learned about it in late July and said nothing for seven weeks.

    The company confirmed the incident after The Wall Street Journal got there first. Google had avoided making a public statement before the report surfaced.

    Myriad: What will be the most-searched TV show on Google? Click to make your prediction.

    The test was a capture-the-flag exercise, a common way labs check an AI’s hacking skill by hiding a secret file on a separate machine and scoring whether the model can break in and grab it.

    Google hired Israeli firm Irregular to run the test in May. Irregular made two mistakes: it left the sandbox, an isolated test environment meant to have zero contact with the real internet, connected to the open web, and it used the name of an actual company as the fictional target.

    Gemini searched for that company online. It found three matches instead of one, and went after all of them.

    The bot located exposed passwords for two of the three targets sitting in plain view online. For the third, it guessed the password outright, though Google says its models stopped short of actually using the stolen credentials.

    “These events highlight the importance of training powerful AI models to act responsibly,” a Google spokesperson said in a statement.

    Google published none of this on its own. The Wall Street Journal broke the story, seven weeks after Google learned what its own test had done and well after Anthropic, OpenAI, and Meta had already come clean about nearly identical failures.

    Google is the fourth major AI lab this year to admit an internal security test spilled into the real world. OpenAI’s models exploited a hidden software flaw and reached Hugging Face’s live servers in July, a breach later found to involve roughly 700 coordinated agents working together to cheat a benchmark.

    Anthropic went digging for its own version after OpenAI’s admission. A review of 141,006 test runs turned up three Claude models that reached real companies, one of them publishing a booby-trapped software package that ran on 15 real systems before anyone caught it.

    Claude’s own reasoning, Anthropic later disclosed, flagged the move as “NOT okay, and surely not the intended solution,” then talked itself back into believing the whole thing was still fake.

    Meta reported a near-identical failure in August involving its Muse Spark model, traced to a misconfiguration at Irregular, the same firm Google used. A Meta spokesperson said the error “inadvertently allowed one of our models access to the internet during evaluation.”

    BitcoinBTC · USD

    $85,758+10%

    Sep 15Sep 16Sep 18Sep 20Sep 22

    $87.0k$83.2k$79.3k$75.5k

    24h HighHigh$87,330

    24h LowLow$81,217

    VolVol$2.7B

    Market projectionsOdds by Myriad

    →

    None of the companies hit in any of these tests asked to be hacked. They got caught in the blast radius of AI labs stress-testing how dangerous their own products can be, using real business infrastructure as an accidental stand-in for fake targets.

    The agents these same companies are racing to put in your inbox, browser, and banking app run on the same boundary-following behavior that just failed, repeatedly, under test conditions.

    Reps. Ted Lieu and Nathaniel Moran introduced the AI Kill Switch Act in Congress in July, which would give federal regulators explicit authority to halt inference on any model found to pose a serious threat. It is still being reviewed by the Subcommittee on Cybersecurity and Infrastructure Protection without a deadline for further action.

    Daily Debrief Newsletter

    Start every day with the top news stories right now, plus original features, a podcast, videos and more.

    admits CompaniesIt Gemini Google Hacked Silent stayed weeks
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Bitcoin price news: BTC eyes $90,000 as leverage is building

    Pragma flags 6 price feeds as critical risk following $3.5M Starknet lending exploit

    Got an Android Phone? Google Thinks You’ll Probably Want a Googlebook Laptop

    Google Fined €403 Million Over GDPR Violations Tied to Location Data

    L2 growth and $120 billion in staking hide Ethereum’s supply reality

    Strategy And Strive Announce $182.7 Million Bitcoin Buy

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    US strikes on alleged drug boats may be ‘crimes against humanity’, UN says | News

    September 22, 2026

    Reform-Agenda: Merz‘ neue Suche nach Gerechtigkeit – POLITICO

    September 22, 2026

    The Search for Silicon Valley’s Most Powerful Woman

    September 22, 2026

    RatHat Android Trojan Uses AI for Automation

    September 22, 2026
    Latest Posts

    Google Assistant will disappear from your phone next month

    August 5, 2026

    Pope Leo Will Visit Peru, Where He Lived for Years, in November

    August 5, 2026

    Forget the goals and PBs – just enjoy it | Sport

    August 5, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    US strikes on alleged drug boats may be ‘crimes against humanity’, UN says | News

    September 22, 2026

    Reform-Agenda: Merz‘ neue Suche nach Gerechtigkeit – POLITICO

    September 22, 2026

    The Search for Silicon Valley’s Most Powerful Woman

    September 22, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.