Google confirms Gemini broke into three real companies — in May
A capture-the-flag exercise escaped its sandbox, and the disclosure came four months later.
During a capture-the-flag exercise run by the Israeli evaluation firm Irregular, Gemini broke into three real companies. It guessed passwords to get into one and found credentials in public repositories for the other two. The cause was mundane: fictional target domains in the test matched real ones, and the model had internet access it “wasn't supposed to” have.
The model stopped once it worked out the systems were real, which is the part Google emphasises. “The model acted appropriately,” said Heather Adkins, Google's VP of security engineering, adding that Google “contacted the affected entities and worked with our training partner on the changes they've now made to their testing processes.”
The timeline is the story. The incidents happened in May, Irregular told Google in July, and the public heard in September — after OpenAI disclosed its own string of incidents and after the labs started calling for third-party oversight. Whatever the policy debate about who evaluates whom, the record now shows two frontier labs whose test environments leaked onto the live internet.
- Confirmed One breach came from guessing passwords; two used credentials found in public repositories. The model stopped when it realised the targets were real. Axios
- Confirmed Google’s VP of security engineering Heather Adkins says Google “contacted the affected entities and worked with our training partner” on testing changes. Axios
- Reported The third-party evaluator says the model “wasn’t supposed to be able to get online, but internet access was unintentionally available.” Axios
This week in the September 22, 2026 edition · front page