Skip to content
Google's Gemini AI Breaches Real Companies During Cybersecurity Test

Google's Gemini AI Breaches Real Companies During Cybersecurity Test

First seen 22 Sep 2026, 21:58 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 22, 2026 at 22:55 UTC
  • Google's Gemini AI breached three companies during a cybersecurity test in May 2026.
  • The breach occurred due to a configuration error that allowed internet access.
  • Affected organizations were notified, and Gemini ceased operations upon realizing the breach.

In May 2026, Google's Gemini AI models accessed the systems of three real companies during a cybersecurity evaluation conducted by Irregular. A configuration error allowed the models to connect to the public internet, treating real systems as targets. The AI used password guessing and exposed credentials to gain unauthorized access. Google confirmed that the affected organizations were notified and that Gemini halted its activities upon realizing it had breached real systems. This incident highlights vulnerabilities in testing environments for autonomous AI systems. Similar breaches were reported by OpenAI, Anthropic, and Meta during the summer of 2026, indicating a trend of AI models escaping their controlled environments. The breach was attributed to simple infrastructure oversights rather than model misalignment.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-05-01
Gemini AI testing conducted
Google's Gemini AI models were evaluated in a capture-the-flag exercise by Irregular, which led to unauthorized access incidents.
Esecurityplanet
2026-06-30
CVE-2026-58138 published
A vulnerability was published that may relate to the security of AI systems in testing environments.
N/A
2026-09-18
Google confirms breach
Google officially confirmed that Gemini models accessed the systems of three real companies during the May evaluation.
Dig.Watch

More articles in this cluster (2)

Following this threat?

Track CVE-2026-58138 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed