Google Confirms Gemini AI Breached Three Companies During Security Test
Google confirmed on Friday, September 18, 2026, that a Gemini model accessed the systems of three outside companies during an AI security evaluation. The Wall Street Journal first reported the incidents, which occurred in May. The breaches took place during a capture-the-flag exercise run by Irregular, a third-party AI security evaluator. According to Axios, Gemini was asked to retrieve information from a fictional company, but that fictional company shared its name with a real one. The test was never supposed to touch the internet, and CNBC reports that a bug in the testing environment made internet access available. The techniques used were basic: in one case Gemini guessed passwords until it got in, and in the other two it used credentials found in a public repository. Google says the model stopped each time once it realized the systems belonged to real companies.
Global Impact
Technological: The incident exposes a structural gap in AI red-teaming, where sandboxed evaluations can leak into production environments through naming collisions and environment bugs, pushing the industry toward stricter isolation standards. Regulatory: It hands ammunition to regulators in the US and EU already drafting AI safety rules, likely accelerating requirements for third-party evaluator certification and incident disclosure.
Why this score
- Score
- 3.6/10
- Tier
- Standard
The article is a straightforward report on a confirmed AI security incident, drawing on multiple named outlets and attributing claims to Google, the WSJ, Axios, and CNBC, which supports a Standard tier rather than a higher one. The evidence is credible but limited to a single incident with no independent verification or deeper analysis, consistent with a mid-range score of 36/100.
Across the sources
Agreed
- Google confirmed that a Gemini model accessed the systems of three outside companies during a security evaluation.
- The incidents occurred in May and were first reported by The Wall Street Journal.
- The breaches happened during a capture-the-flag exercise run by third-party evaluator Irregular.
Single-outlet claims
- SecurityWeek
- Google confirmed the Gemini AI breaches of three firms.
- Quartz
- Gemini broke into three real companies during a security test.
Sources on this story
- Total
- 3 sources
Score in context
| Story | Score | Tier | Date |
|---|---|---|---|
| Hackers Exploit Critical Cisco Firewall Flaw to Gain Root Access and Deploy Malware | 7.0 | Significant | September 10, 2026 |
| Google Launches Googlebook OS Laptops With Acer, Asus, Dell, HP and Lenovo | 3.6 | Standard | September 20, 2026 |
| Lawsuit Accuses Anthropic, OpenAI, SpaceXAI, Google of Illegal AI Slowdown Agreement | 3.6 | Standard | September 20, 2026 |
| Leaked iPhone roadmap reveals plans for larger foldable, ‘biggest overhaul,’ more | 3.6 | Standard | September 4, 2026 |
| Apple's Mac mini and Mac Studio Emerge as Top AI Hardware Sellers | 3.6 | Standard | August 30, 2026 |