Google says Gemini reached three real company systems after a test environment was mistakenly left open to the public internet

Google says Gemini reached three real company systems after a test environment was mistakenly left open to the public internet

N
News Editor
2026-09-19 01:23:04
Google said Gemini entered the systems of three real companies during a cybersecurity evaluation after a third-party testing setup was mistakenly exposed to the public internet. According to the report cited by BlockBeats, the model accessed one company by guessing a password and reached two others after finding login credentials in public code repositories. In each case, Gemini stopped once it determined the targets were real companies. Google said the incident did not involve a sandbox escape. The public-facing access path was already open because of a configuration error in the evaluation environment run by Irregular, the third-party testing firm involved. The report also said a simulated company used in the test shared a name with a real company, which led Gemini from the assigned task into actual external systems. Irregular said the issue matched similar incidents seen in earlier evaluations involving other labs. Anthropic, OpenAI and Meta had previously encountered related problems in Irregular-run tests. Anthropic and OpenAI both said those incidents were caused by public internet access being left enabled, while OpenAI added that there was no complex sandbox escape and no zero-day exploit. Independent outlet Effort criticized the way such incidents were later framed as stories about “rogue” or “out-of-control” models.

Google said Gemini entered the systems of three real companies during a cybersecurity evaluation.

According to a report cited by BlockBeats, Gemini got into one company by guessing a password. In the other two cases, it found login credentials in public code repositories. The model stopped in all three cases after determining that the targets were real companies.

The issue was an internet-exposed test setup

The incident did not involve a sandbox escape, Google said, because the public internet entry point was already open. The problem was traced to Irregular, the third-party evaluation firm. The test was not supposed to have internet access, but a configuration mistake allowed the model to connect directly to the public web.

The report added that a simulated company used in the exercise shared the same name as a real company, and Gemini followed the task path into actual external systems.

Irregular linked it to earlier incidents

Irregular said the case was the same type of issue seen in similar incidents involving other labs. Anthropic, OpenAI and Meta had previously run into related problems in Irregular evaluations.

Anthropic and OpenAI both said those incidents were caused by test environments that had public internet access mistakenly left on. OpenAI also stressed that there was no complex sandbox escape and no use of a zero-day vulnerability.

Effort challenged the later framing

Independent outlet Effort criticized the way these incidents were later packaged as stories about “out-of-control” models.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.