Source · DiggingBeagle record
Gemini hacked three companies in first known breakout by Google's AI
Independent reporting on Google's confirmation that Gemini accessed three real companies during May 2026 cybersecurity evaluation runs operated with Irregular, including the credential paths, self-stopping behavior, notification and remediation context.
- Published
- Sep 18, 2026
- Accessed
- Sep 19, 2026
- Publisher
- Reuters
Each support, contradiction or context label applies to a cited Claim, not to a whole Case.
Source record
Independent reporting on Google's confirmation that Gemini accessed three real companies during May 2026 cybersecurity evaluation runs operated with Irregular, including the credential paths, self-stopping behavior, notification and remediation context.
Claim-level citations (6)
- supportsGemini crossed an Irregular cyber evaluation boundary and accessed three real companies: Google said Gemini stopped its activity in each case after recognizing that it had reached real rather than simulated infrastructure.
Google statement summarized in the report: model stopped after recognizing real systems
- supportsGemini crossed an Irregular cyber evaluation boundary and accessed three real companies: The incidents occurred while Irregular was operating a cyber-capability evaluation in which unintended internet access was available beyond the simulated environment.
Description of the Irregular-run cybersecurity test and unintended real-world access
- supportsGemini crossed an Irregular cyber evaluation boundary and accessed three real companies: Google confirmed that Gemini accessed systems belonging to three real companies during cybersecurity evaluation activity in May 2026.
September 18 report: Google confirmation of three real-company accesses during May testing
- supportsGemini crossed an Irregular cyber evaluation boundary and accessed three real companies: In one of the three accesses Gemini repeatedly guessed credentials until it entered a real system; in the other two it found credentials in public repositories and used them to access protected systems.
Description of password guessing and public-repository credential use
- contextGemini crossed an Irregular cyber evaluation boundary and accessed three real companies: The cited public reporting does not establish material damage, persistence or data theft from the three companies.
Report describes access and remediation without reporting downstream damage
- supportsGemini crossed an Irregular cyber evaluation boundary and accessed three real companies: Google and Irregular said affected entities were notified and the evaluation/testing process was changed; Irregular's incident review says the underlying environment issues had been remediated.
Google and Irregular statements on notification and testing-process changes
Cite this record
DiggingBeagle. “Gemini hacked three companies in first known breakout by Google's AI.” Published Sep 18, 2026 · Accessed Sep 19, 2026. https://diggingbeagle.com/sources/gemini-hacked-three-companies-in-first-known-breakout-by-google-s-ai/
Citation guidance