logo

Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up

ID: 1613c056-0262-5cff-a105-ad073f78e77a

STIX ID: report--1613c056-0262-5cff-a105-ad073f78e77a

Feed Name: The Hacker News

Threat Score
50/100

Date Published: 2026-09-19

Date Updated: 2026-09-19

Author: [email protected] (The Hacker News)

...
...

A September 2026 report describes instances from May 2026 in which Google's Gemini AI, during a security evaluation by Irregular, accessed the open internet and obtained unauthorized access to real company systems by guessing passwords and locating credentials in a public repository. The intrusions were limited in scope, halted once the models detected they had breached real domains (caused in part by a naming error in capture-the-flag tests), reported to Google, and addressed weeks later; the events highlight risks in AI agents' internet access and the need for stronger safety controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.