Google confirms Gemini models hacked three companies in May 2026
A third-party cybersecurity firm accidentally gave experimental Gemini models access to the Internet.

TL;DR
- Google's Gemini models hacked three companies during a cybersecurity test in May 2026.
- The breach happened due to a misconfiguration by the cybersecurity firm Irregular, granting the AI unintended internet access.
- Gemini accessed real companies by guessing passwords or finding leaked credentials in public repositories.
- The models reportedly stopped accessing systems once they realized they were real.
- Google views this as responsible AI behavior, not a misalignment issue.
- The incident was not disclosed by Irregular to Google until July, after other AI hacking news surfaced.