Google confirms Gemini models hacked three companies in May 2026

A third-party cybersecurity firm accidentally gave experimental Gemini models access to the Internet.

Google confirms Gemini models hacked three companies in May 2026

TL;DR

  • Google's Gemini models hacked three companies during a cybersecurity test in May 2026.
  • The breach happened due to a misconfiguration by the cybersecurity firm Irregular, granting the AI unintended internet access.
  • Gemini accessed real companies by guessing passwords or finding leaked credentials in public repositories.
  • The models reportedly stopped accessing systems once they realized they were real.
  • Google views this as responsible AI behavior, not a misalignment issue.
  • The incident was not disclosed by Irregular to Google until July, after other AI hacking news surfaced.