Google says Gemini breached three real companies after a security test accidentally exposed internet access
Google has acknowledged that Gemini entered the systems of three real companies during a security exercise that was supposed to run in an isolated, offline environment. According to the report, the incident happened after a fictional company used in the test shared a name with a real business and public internet access was mistakenly left enabled. Gemini then targeted the real-world company instead of the sandbox target. The model reportedly used basic techniques rather than advanced exploits. In one case, it guessed weak passwords to access an online service. In two others, it searched the web, found public code repositories, and used exposed credentials that had been uploaded by mistake, including account details, passwords, and keys. Google said Gemini stopped after recognizing the targets were real companies and argued that the episode resembled vulnerability discovery rather than uncontrolled behavior. That explanation has drawn criticism. Corridor CEO Jack Cable said Google was leaning on the norms of responsible disclosure without the prior authorization that usually defines legitimate white-hat testing. The report also places the Gemini case alongside earlier incidents involving Anthropic, OpenAI, and Meta, and says all four cases were tied to evaluation provider Irregular, raising broader questions about test isolation, access controls, and how frontier AI systems are constrained during cyber exercises.








