Google says Gemini breached three companies during security test
Google’s artificial intelligence model Gemini accessed computer systems belonging to three real companies without authorization during a cybersecurity test in May, the company has confirmed.
Gemini gained access in one case by repeatedly guessing a password and by using credentials that had been exposed in a public repository in two others.
Google said that the affected companies were informed about the breaches. The companies have not been named.
The incidents, first reported by The Wall Street Journal, are the latest disclosures involving AI models compromising real-world computer systems during cybersecurity evaluations run by Irregular.
The cybersecurity firm also ran evaluations in which AI models from Anthropic, OpenAI and Meta did the same.
In August, Irregular declined to say whether any other clients had been affected by the company mistakenly giving the AI tools access to the public internet during a hacking exercise.
It is not known if any other hacking incidents have occurred as a result of Irregular’s error nor whether any affected organizations are considering legal action. It also remains unclear if regulators or law enforcement are investigating the incidents.
The company was criticized after publishing a postmortem that did not disclose the total number of incidents.
Alan Woodward, a computer science professor at the University of Surrey, said Irregular’s publication was “not what I think of as a technical report,” adding there was “a lot of marketing spin in there.”
Irregular said at the time there were “no active issues today” involving its evaluations. The company said it plans to publish a white paper on best practices for evaluation security but did not provide a publication date.
The incidents at Irregular are separate from two other recent cases involving AI agents acting against real-world targets.
Britain’s AI Security Institute reported that Anthropic’s Mythos 5 model created fake online personas, planted malicious code in a real software project and sent phishing emails to real developers as part of an evaluation that allowed those models access to the internet.
OpenAI previously confirmed that its models breached Hugging Face’s production infrastructure after escaping a sandboxed testing environment. Unlike the Irregular incidents, which stemmed from a testing-environment misconfiguration, the OpenAI models exploited a vulnerability to escape their isolated environment.
Alexander Martin
is the UK Editor for Recorded Future News. He was previously a technology reporter for Sky News and a fellow at the European Cyber Conflict Research Initiative, now Virtual Routes. He can be reached securely using Signal on: AlexanderMartin.79



