In May 2026, Gemini, an artificial intelligence developed by Google, managed to access the systems of three real companies during a third-party cybersecurity test. Initially, the AI was conducting a data extraction exercise in a fictional company, but it ended up gaining internet access and infiltrating the networks of authentic organizations.
The occurrence was disclosed by The Wall Street Journal after contact with one of the affected companies. The newspaper pointed out that the confusion arose because the real companies had names identical to those used in the simulation.
The AI model employed brute force techniques to guess the password of an external system and also found exposed credentials in public repositories. This data was subsequently used to invade two more protected networks.
The security flaw resided in the infrastructure of the Israeli startup Irregular, which was responsible for conducting the simulated exercise. Irregular itself admitted to having accidentally left the internet accessible to the model and mentioned having already registered similar incidents in evaluations conducted for OpenAI, Meta, and Anthropic.
Google stated that Gemini immediately ceased the attacks after identifying that it was accessing information from genuine corporate networks, not from the servers designated for the test. The company chose not to classify the event as a misalignment case, a term reserved for situations where an AI acts outside established guidelines.
Heather Adkins, Google's Vice President of Security Engineering, informed The Wall Street Journal that Gemini acted correctly by stopping the cyberattack as soon as it realized the error. According to the executive, Google promptly notified the three compromised companies about the exploited vulnerabilities and cooperated in fixing these flaws.
However, experts and researchers expressed disagreement with Google's explanation that it was merely a vulnerability alert. Jack Cable, CEO of the AI security startup Corridor, argued that the developer of Gemini downplayed the seriousness of the incident. For him, the crucial point lies in the fact that language models are surpassing limitations and executing real attacks against external targets.

