- Sep 22, 2026
- 1 min read
Google Gemini Accessed Three Companies’ Systems in Security Test
Google’s Gemini accessed the systems of three real companies during a cybersecurity test after an error allowed the model to connect to the public internet.

Google’s Gemini AI model accessed the systems of three real companies during a cybersecurity test in May after an error allowed the model to connect to the public internet.
The test was run by cybersecurity company Irregular and was designed as a simulated “capture the flag” exercise. Gemini was supposed to work with fictional targets, but a configuration error gave it internet access. The model then used publicly available information and exposed credentials to reach systems belonging to three real companies.
In one case, Gemini guessed a password to access a company’s system. In two others, it found credentials that had been exposed in databases. According to the security researchers, the model then carried out reconnaissance and other actions against the systems.
Gemini stopped its activity in all three cases after determining that the systems were not part of the simulated exercise. Irregular notified the affected companies, and Google said it caused no damage.
Google’s vice president of security engineering, Heather Adkins, confirmed the incidents and said the company changed its testing procedures after the evaluation. Google did not initially disclose the incidents publicly, saying the activity was contained and the affected organizations were notified.
The incident is the first publicly reported case of a Google AI model independently accessing and compromising real third-party systems. These cases are fueling concerns among security researchers about testing increasingly autonomous AI systems that have access to real networks, as seen in the recent cases with OpenAI and Anthropic.
Relevant articles
- news
- 5 days ago
- 1 min read
OpenAI has disclosed six cases of “unexpected or concerning” behavior by its AI models over the past six months.

- news
- Yesterday
- 1 min read
California has passed a package of child-safety laws expanding age-assurance requirements for social media platforms and AI services.

What is Sumsub anyway?
Not everyone loves compliance—but we do. Sumsub helps businesses verify users, prevent fraud, and meet regulatory requirements anywhere in the world, without compromises. From neobanks to mobility apps, we make sure honest users get in, and bad actors stay out.


