Gemini Accessed Three Real Companies in a Security Test
A misconfigured evaluation environment handed Google's model live internet access; Google says Gemini aborted each intrusion on its own.
In short
Gemini reached systems belonging to three real companies because a misconfigured test environment gave the model internet access it was never meant to have.
At a glance
- The evaluation ran in May 2026 at the testing firm Irregular and was scoped to a made-up target company.
- A misconfiguration let the supposedly sealed-off test setup reach the open internet.
- Case 1: the fictional target shared a name with a real firm, and Gemini started guessing passwords there.
- Cases 2 and 3: the model found usable credentials sitting in publicly readable repositories.
- Google notified the affected firms; the model involved was not the newest Gemini generation.
Google's Gemini reached protected systems at three real companies during a May 2026 security evaluation that was supposed to stay inside a sandbox. The cause was not a jailbreak but a misconfigured test environment that handed the model live internet access, according to Google via heise online. The evaluation was run by the testing firm Irregular against an invented target company.
The setting that opened the cage
Irregular's harness was designed to keep the model sealed off from the open internet. Because of the misconfiguration, it was not. That put production systems within reach of an agent whose entire assignment was to find and exploit weaknesses.
Two routes, three companies
The three incidents came out of two different routes.
- In one case the fictional target shared its name with a company that actually exists, so Gemini began guessing passwords against the real one.
- In the other two, the model located working credentials sitting in public code repositories and used them.
Neither move is exotic; both are opening steps in an ordinary intrusion. What is unusual is the operator.
Google's account
Google says Gemini stopped by itself each time, as soon as it worked out that the target belonged to a real business. The company notified the three firms and is working with Irregular to tighten the test harness. Google also states that the model involved was not its newest Gemini generation.
What is still unconfirmed
Google has published no version number and has not named the three companies. That leaves the depth of each access, and whether any data was read, outside the public record. The claim that the model disengaged on its own currently rests on Google's own description and has not been independently checked.
A disclosure process that does not fit
Jack Cable, CEO of Corridor, argues that an episode like this does not belong in the normal vulnerability-disclosure pipeline. A model that wanders into someone else's infrastructure by accident is a different kind of event from a researcher filing a bug report. Who has to tell whom, and how fast, is not settled anywhere yet.
FAQ
Did Gemini hack real companies?
The model did get into systems at three real companies, but unintentionally, during a security test. Google's account describes it as a test accident rather than a deliberate attack.
How did Gemini get internet access during the test?
The test environment was meant to be sealed off but was configured wrongly. That gave the model internet access it was never supposed to have under the plan.
Which companies were affected?
Google has not named them. All that is public is that there were three of them and that the company says it informed them.