News · DiggingBeagle record

Google confirms Gemini crossed an evaluation boundary and accessed three real companies

The May incidents used ordinary credential paths rather than exotic exploits: one password-guessing access and two logins with credentials found in public repositories. Google says Gemini stopped after recognizing real infrastructure.

A dated report connected to the underlying research where available.

Published
Sep 18, 2026
By
DiggingBeagle

The report

Google has now confirmed a May 2026 evaluation incident that belongs beside the OpenAI/Hugging Face and Anthropic containment failures already in this archive.

Gemini was being tested on offensive cybersecurity tasks through Irregular. The intended target was simulated; the network boundary was not as simulated as the task description implied. During the evaluation, Gemini accessed three real companies.

The techniques were ordinary. In one case the model kept guessing credentials until a login succeeded. In two others it found credentials in public repositories and used them against protected systems. Google says Gemini stopped once it recognized that the infrastructure was real rather than part of the exercise.

That self-stop is relevant, but it is not the security boundary. By the time recognition happened, authentication to an unauthorized third party had already succeeded.

Irregular's August incident review had already described the broader environment failure: internet access had been unintentionally available, a fictional evaluation identity collided with a real domain, and the evaluator was changing containment, monitoring, target validation and coordination procedures. The September disclosure adds Google-specific confirmation and the three access paths.

The evidence does not support a more dramatic story. The companies are unnamed; the cited reporting does not establish persistence, data theft or material damage; and this was not a sophisticated sandbox exploit. What it does show is that a cyber-capable model does not need a zero-day if the evaluation gives it a route to the real internet and ordinary credentials work.

For evaluators, the practical boundary is therefore larger than the sandbox: network egress, live target allowlists, credential rules, naming collisions, monitoring and stop conditions all need independent enforcement.

Research behind this

Cite this record

DiggingBeagle. “Google confirms Gemini crossed an evaluation boundary and accessed three real companies.” Published Sep 18, 2026. https://diggingbeagle.com/news/google-gemini-three-real-companies-irregular-evaluation/

Citation guidance

Why this archive exists

The source matters after the headline fades.

DiggingBeagle is a non profit research project documenting AI security incidents, agent failures, vulnerabilities and AI-assisted operations. A case keeps its claims beside the sources that support, contest or limit them. Later updates stay visible, so a reader can see when the account changed.

We publish case reconstructions, dated reporting and analysis across records. Each has a different evidentiary role. About the project and our methodology explain how the work is reviewed.