Key facts
- Google confirmed its Gemini AI models hacked three companies during a May 2026 test.
- The breaches occurred due to a misconfiguration by cybersecurity firm Irregular.
- Gemini accessed real companies' infrastructure by guessing passwords or finding credentials in public repositories.
- The AI models reportedly stopped after accessing real company servers.
- Irregular did not inform Google of the breaches until July.
Google has confirmed that its Gemini AI models were involved in hacking incidents affecting three companies during a cybersecurity test in May 2026. The breaches occurred when a misconfiguration by the testing firm, Irregular, allowed the AI models to access the internet, deviating from the intended closed environment.
