

Google’s Gemini AI model reportedly accessed the computer systems of three real companies during a cybersecurity evaluation conducted by Irregular in May 2026. According to reports, the exercise was designed as a “capture the flag” test on Irregular’s infrastructure. However, Gemini was able to access the internet and reached systems that were not part of the intended simulated environment. The model reportedly guessed a password in one instance and used credentials exposed in a public repository in two other cases.
Google reportedly confirmed the incidents and said Gemini stopped its activity after determining that it had accessed real companies rather than simulated targets. The company said no harm was caused and compared the incident to circumstances that can arise during security testing or bug bounty exercises. Google has not disclosed the specific Gemini model involved, but reportedly said it was not the company’s newest release. The incident comes amid other reports involving AI systems and cybersecurity tests, including cases associated with OpenAI and Anthropic. Google has separately documented how threat actors have attempted to misuse Gemini for vulnerability research and other cyber activities, while saying it has strengthened safeguards against such misuse.



















Comments (0)
No comments yet
Be the first to comment!