SecureITWorld (1)
Sign Up

We'll call you!

One of our agents will call you. Please enter your number below

JOIN US



Subscribe to our newsletter and receive notifications for FREE !





    By completing and submitting this form, you understand and agree to SecureITWorld processing your acquired contact information as described in our Privacy policy. You can also update your email preference or unsubscribe at any time.

    SecureITWorld (1)
    Sign Up

    JOIN US



    Subscribe to our newsletter and receive notifications for FREE !





      By completing and submitting this form, you understand and agree to SecureITWorld processing your acquired contact information as described in our Privacy policy. You can also update your email preference or unsubscribe at any time.

      Google Gemini AI Hacks Three Real Companies Found During a Cybersecurity Test

      Gemini AI hacked 3 real companies

      Google's Gemini AI hacked 3 real companies during a cybersecurity test conducted by Irregular, an AI security evaluation firm. Google was notified about the incidents in late July 2026; however, the company did not disclose anything publicly. They confirmed the breaches in the last week, after the Wall Street Journal reached out for comment ahead of publishing its reports.

      Gemini Crossed the Boundaries of the Cybersecurity Tests

      Google has later confirmed the incidents, occurred during a “capture the flag” challenge, wherein Gemini’s ability was tested to find information inside a simulated network of a fictional company.

      The testing environment was aimed at being isolated from the public internet. However, an unintended internet connection allowed the model to move beyond the intended environment. Here, a naming issue allowed Gemini to go beyond the simulated environment.

      The company used in the exercise shared its name with a real organization, allowing the model to identify internet-accessible systems associated with the real company as potential targets within the test.

      How did Gemini Access the Three Companies?

      In one case, the AI model guessed the passwords repeatedly until it got in and used found credentials in a public repository and used them to log in to the other two. In all three cases, the AI model had stopped its activity in all the three cases after knowing it had accessed a real company’s systems, Google said.

      Google Confirmed that No Damage Was Caused

      Google has confirmed that the incidents caused no harm and also noted Gemini stopped on its own once it has realized it had breached real companies rather than simulated environments. Google’s Vice President of Security Engineering, Heather Adkins, said the incident shared the importance of training advanced AI systems must be trained to act responsibly.

      Enhancing Security Around AI Testing

      The incident stands as a major push involving AI systems accessing real-world infrastructure during cybersecurity evaluations. Organizations should implement the necessary safeguards like least privilege access, multifactor authentication, short-lived credentials, outbound connection controls, strict domain allowlists, and automatic shutdown when an AI agent connects with an unauthorized system.

      There is a growing case for safety testing that does not depend solely on instructions given to AI models. Effective oversight needs layered controls, authorization, real-time intervention, and automatic shutdown when an agent comes in contact with an unauthorized asset.

      The Gemini incident highlights how AI agents can cross testing boundaries when all the technical safeguards in place fail. It follows the reports of AI models such as OpenAI in Hugging Face hack, and even Anthropic’s Claude involved in hacking real systems. The three companies affected have not been publicly identified.

      For all the trending news around the technology and cybersecurity world, visit our site now.


      Recommended For You:

      Are Google AI Overviews Destroying Your Website Traffic Here’s the Truth





        By completing and submitting this form, you understand and agree to SecureITWorld processing your acquired contact information as described in our Privacy policy. You can also update your email preference or unsubscribe at any time.

        Popular Picks


        Recent Blogs

        Recent Articles

        SecureITWorld (1)

        Contact Us

        For General Inquiries and Information:

        For Advertising and Partnerships: 


        Copyright © 2026 SecureITWorld . All rights reserved.

        Scroll to Top