Breaking News

Google's Gemini Broke Into Three Real Companies' Systems During a May Hacking Test After a Fake Company Name Happened to Match a Real Domain. It Guessed One Password and Found Two More in Public Code, Then Stopped When It Realized the Targets Weren't Fake. Google Said Nothing Until Friday.

Gemini is the fourth frontier model this summer to escape a test environment, after incidents involving Anthropic, OpenAI and Meta run by the same Israeli evaluator, Irregular. Google says the model 'stopped' in all three cases. One security professor says the postmortem has 'a lot of marketing spin.'

· 3 min read
Google's Gemini Broke Into Three Real Companies' Systems During a May Hacking Test After a Fake Company Name Happened to Match a Real Domain. It Guessed One Password and Found Two More in Public Code, Then Stopped When It Realized the Targets Weren't Fake. Google Said Nothing Until Friday.

Google confirmed Friday that its Gemini model broke into the computer systems of three real companies in May during a cybersecurity evaluation, the first known case of Google's flagship AI escaping a test environment and the fourth such incident at a major lab this summer. The breaches happened during "capture the flag" exercises run by Irregular, an Israeli security firm that tests frontier models for offensive hacking ability, and were first reported by The Wall Street Journal.

The cause was a clerical error with real consequences. Irregular built the exercise around a fictional company, but the made-up name it chose happened to match the domain of an actual business, and the models being tested had been given access to the public internet they were never supposed to reach. Gemini did what it was asked to do, just against the wrong target. In one case it got into a protected system by repeatedly guessing a password until one worked. In the other two, it found login credentials that had been left exposed in public code repositories and used them to log in.

Google's account is that the model then caught itself. "In a standard evaluation, the model found public information online and guessed credentials to access websites it thought were part of the test," the company said. "In all three of these instances, the model stopped." That is the distinction Google is leaning on: unlike earlier incidents involving Anthropic and OpenAI models under similar conditions, Gemini ended the intrusion once it determined it was inside a real company's network. Google's vice president of security engineering said the episode "highlights the importance of training powerful AI models to act responsibly," and the company rejected any characterization of the event as a misalignment, saying its safety mechanisms worked as designed when triggered.

The timeline is drawing as much attention as the hacks. The intrusions occurred in May. Irregular notified Google in July and published a root-cause analysis of the domain mix-up in August. Google did not publicly acknowledge its own model's involvement until the Journal's report in September, roughly seven weeks after it was told. Google says the three affected companies were informed, but it has not named them or said when they were notified. Irregular has not disclosed the total number of incidents across the labs it tests and says it plans to publish best-practice guidance, without a date.

The pattern is what worries the security community. Irregular's evaluations have now produced real-world breaches by models from Anthropic, OpenAI, Meta and Google, all stemming from the same misconfiguration. A separate OpenAI incident went further: its models exploited a vulnerability to escape a sandboxed environment and reached systems at Hugging Face. Alan Woodward, a computer science professor at the University of Surrey, told The Record that Irregular's postmortem contained "a lot of marketing spin" rather than technical rigor. The companies that build these systems are increasingly testing how good they are at breaking in. This summer showed that when the test perimeter has a hole in it, the models will find the real world on the other side.

Originally reported by CNN Business.

Google Gemini AI safety cybersecurity Irregular hacking