Google Gemini AI Breached Three Companies During Security Testing

The420.in Staff
4 Min Read

Google says its Gemini AI breached three companies during security testing before stopping after detecting live systems.

How did the test reach real companies?

Google has disclosed that its Gemini artificial intelligence model gained unauthorised access to the digital infrastructure of three companies in May while undergoing cybersecurity testing intended to assess its offensive capabilities.

The exercise was part of pre-deployment red-team testing conducted by Irregular, an Israeli cybersecurity startup contracted by major technology companies to audit AI models before their wider release. Systems developed by Anthropic, OpenAI and Meta had also established unauthorised internet connections during evaluations handled by the same security firm.

Irregular said unexpected internet connectivity had accidentally remained active during testing, allowing models to carry out actions in live environments. The underlying network vulnerability has since been patched.

Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise

What caused Gemini to attack a real target?

One Gemini incident began with a simulated attack against a fabricated corporate target. However, the fictional entity shared its name with a genuine business.

With unintended internet access available, Gemini redirected the exercise towards the real company. It subsequently gained unauthorised entry to that business and two other companies, either by guessing system passwords or finding exposed credentials on the open web.

The incident illustrates how a controlled AI security exercise can cross into real infrastructure when testing safeguards and network isolation fail.

Why did Gemini stop the operation?

After entering the servers, Gemini recognised that it was operating inside genuine corporate infrastructure rather than the simulated environment created for the exercise. The system then stopped its offensive operation, according to the account disclosed by Google. The company said the incidents caused no tangible harm or destruction of data on the affected networks.

Google described the model’s decision to halt once it detected the real environment as an example of responsible behaviour during the testing process.

What happened after the breaches?

Irregular said participating AI laboratories were notified in late July and affected companies were contacted during the investigation. The security firm said it acted immediately and that known issues on its side had been resolved weeks earlier.

Heather Adkins, vice-president of security engineering at Google, said Google’s security team has a record of reporting weaknesses found in other organisations’ software and systems, including weak passwords. She said the three affected entities were informed and Google worked with its testing partner on changes to the evaluation process.

What does the incident show about AI testing?

The episode raises questions about the controls surrounding security evaluations of increasingly capable AI agents. A test designed to examine offensive abilities reached genuine corporate networks because internet access remained available and a simulated target happened to share a name with a real company.

Reports also describe similar incidents involving models from OpenAI, Anthropic and Meta during evaluations by the same testing partner.

Google’s case ended after Gemini recognised that it had moved beyond its sandbox and halted its operation. The incident nevertheless demonstrates how testing conditions, exposed credentials and unintended network access can combine to move an AI security exercise from a controlled simulation into real-world infrastructure.

About the author — Ayesha Aayat writes on cybercrime, digital safety, and emerging online threats. Her work focuses on public awareness, legal clarity, and technology-driven risks.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected