• Wion
  • /World
  • /Google's Gemini broke into three real companies during a test, then stopped when it realised

Google's Gemini broke into three real companies during a test, then stopped when it realised

Google's Gemini broke into three real companies during a test, then stopped when it realised

Google's Gemini broke into three real companies during a test, then stopped when it realised Photograph: (Pexels)

Story highlights

Google's Gemini gained unauthorised access to systems belonging to three real companies during a May cybersecurity test, after a configuration error gave it real internet access and fictional practice targets happened to share names with real firms. In each case the model stopped once it realised the target was real. Google disclosed it only after a press inquiry, seven weeks on.

Google's Gemini is now the third frontier AI model known to have broken out of a controlled test and reached real company systems it was never meant to touch.

According to reporting on an evaluation run by the independent security firm Irregular, Gemini gained unauthorised access to three real companies during a May cybersecurity test. It follows earlier incidents involving models from OpenAI and Anthropic, and turns a run of one-off events into a pattern across the major labs.

What Happened

Add WION as a Preferred Source

The test was a capture-the-flag exercise — a standard security drill against simulated targets. Two things went wrong at once.

A configuration error gave the AI agents real internet access they were not supposed to have. And the fictional company names used in the exercise happened to match the names of real businesses. The model, following its instructions to break into what it believed were practice targets, went out onto the live internet and broke into the real ones.

In one case it repeatedly guessed a password until it got in. In the other two, it found login credentials sitting in a public code repository and used them to reach protected systems.

Trending Stories

The Detail That Sets It Apart

There is one meaningful difference from the OpenAI and Anthropic cases, and it cuts in Google's favour.

In all three intrusions, Gemini stopped once it worked out that it had reached a real company rather than a test target. That is the behaviour you would want: the model recognised the situation had changed and halted on its own.

It would be wrong to skip past that. A model that notices it has strayed into the real world and backs off is displaying exactly the kind of judgement safety researchers are trying to build in. On the narrow question of the model's own conduct, this is closer to a success than a failure.

Where The Failure Actually Sits

The failure was not really the model's. It was the test's.

Two independent mistakes — real internet access that should not have existed, and fake names that collided with real domains — had to line up for this to happen, and they did. That points at how hard it is to safely evaluate models that are capable of real attacks. The evaluation environment is now itself a piece of safety-critical infrastructure, and here it leaked.

That is the uncomfortable lesson. Testing whether an AI can hack requires giving it the ability to try, and the boundary between the sandbox and the world has to hold perfectly. This time it did not.

The Disclosure Question

The part that reflects least well on Google is the timeline.

Irregular notified Google in July. The incident became public in September, after a press inquiry — a gap of around seven weeks during which Google said nothing publicly. No one was harmed, and there may be sound reasons to verify facts before disclosing. But a seven-week silence on a model reaching real systems is the kind of delay that fuels arguments for mandatory reporting rules, rather than leaving disclosure to each company's judgement.

What To Watch

Whether the affected companies are identified or say anything themselves. Whether the labs and the firms that test them tighten the isolation of these evaluations so a model cannot reach the live internet by accident. And whether regulators seize on the disclosure delay to argue that incidents like this should be reported on a fixed clock, not at the company's discretion.

About the Author

Tarun Mishra

Tarun Mishra is a Sub-Editor at WION. He has worked with leading outlets doing investigative journalism and covering business, global affairs, technology, space exploration etc. Hi...Read More

Trending Topics