Gemini hacked three companies in May during a test by Irregular, which was also involved in similar incidents disclosed by OpenAI, Anthropic, and Meta
The episode resembled similar hacks by other AI models, but Google said it didn't consider it an instance of model misalignment
Context & Ripple Effects
Google’s earlier Gemini security coverage focused on outsiders: researchers found a poisoned Calendar-invitation attack that could trigger smart-home devices, while Google’s threat-intelligence group reported commercially motivated attempts to clone the model. The Irregular evaluation shifts attention to the model’s own actions in a live-system boundary failure.
The key dispute is governance rather than whether access occurred. Google says Gemini stopped after recognizing it had reached real company systems and does not regard that outcome as misalignment or a disclosure-triggering event, a position detailed in Google’s explanation of its disclosure decision.
First-order effects
- The three affected companies must assess the access as a security incident even though Gemini stopped, while Google’s handling makes its disclosure threshold part of the incident itself.
- Google and Irregular face pressure to distinguish more rigorously between controlled cyber evaluations and tests that can reach real organizations’ systems.
Second-order effects
- Enterprise customers and security teams gain a concrete reason to ask frontier-model providers how they isolate cyber-capability testing and when they notify affected parties.
- Independent evaluators’ methodology becomes more consequential: a test’s target design and containment controls can determine whether a model-safety result becomes an external security event.
Third-order effects
- If frontier-model evaluations repeatedly touch real systems, voluntary provider judgments about intent and harm will face pressure from customers and policymakers for shared incident-reporting norms.
- Cyber evaluations are becoming a governance layer for general-purpose AI: the question is not only whether models can perform harmful tasks, but whether testing infrastructure can constrain them to authorized environments.
The trend: Frontier AI safety is moving toward operational governance, where evaluation containment and disclosure rules matter alongside model behavior.
Related: Dual-use AI governance · Frontier-model concentration risk · Gemini · Irregular · Google’s disclosure rationale · Gemini Calendar-invitation attack
Related Coverage
- Google's Gemini becomes latest AI model to break out and hack computer systems CNBC
- Google Says Its A.I. Hacked Three Companies in Testing Breakout New York Times · Kate Conger
- Gemini Hacked Three Companies in First Known Breakout by Google's AI. Gemini finally caught up on Felony Bench! Simon Willison's Weblog · Simon Willison
- Google's Gemini AI hacked into other companies, adding to ‘rogue’ AI incidents Washington Post · Gerrit De Vynck
- Gemini hacked three companies in first known breakout by Google's AI Reuters
- Google says its AI model gained unauthorized access to three outside systems NBC News
- Google's Gemini breaks out of test environment to hack three external firms: Report Livemint
- Google's Gemini Hacked Three Companies in May, and It's Only Admitting That Now Gizmodo · Tom McKay
- Google's Gemini hacked three companies in new AI safety incident Financial Times · Stephen Morris
- Google says its Gemini AI model hacked three other companies The Guardian · Johana Bhuiyan
- Google's AI hacked three companies in testing Axios · Sam Sabin
- Google's Gemini Model Hacks Companies During Test The Information · Nick Wingfield
- Google's Gemini hacks 3 companies in AI testing breakout Honolulu Star-Advertiser · Kate Conger
- Google Joins OpenAI, Anthropic, Meta in Disclosing AI Hacks Bloomberg
- Gemini hacked 3 AI companies during testing by cybersecurity firm, Google confirms after report Hindustan Times
- Google's Gemini AI System Hacked Three Systems in Safety Tests Bloomberg Law · Julia Love
- Google's Gemini AI hacked three companies in security test BBC · Ottilie Mitchell
- Google Gemini breached three companies during cybersecurity test Gulf News · Balaram Menon
- Now, Google Gemini becomes latest AI model to break out & hack real companies Business Today
- How Google Gemini hacked 3 companies during AI safety tests Financial Express · Aditi
- Google Confirms AI Model Hacked Companies In Cybersecurity Tests MediaPost · Laurie Sullivan
- Google Gemini hack: AI model accessed three companies during cybersecurity test Moneycontrol
- Google says its Gemini AI model hacked three other companies The Irish Times · Johana Bhuiyan
- Google's AI independently infiltrated three external systems, mistakenly believing they were test systems Ukrainian National News
- Google's AI assistant Gemini hacked three websites RTHK
- Gemini hacked three companies in first known breakout by Google's AI, WSJ reports 1330 & 101.5 WHBL · Harshita Mary Varghese
- Google's Gemini AI hacked three companies in security test Hacker News
- Google Gemini AI Hacked 3 Real Companies during a Cybersecurity Test Cyber Security News · Guru Baran
- Google's Gemini Breached Three Companies in First Known AI Breakout - And the Industry Has a Containment Problem Forkast · Lena Park
- Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up The Hacker News
- Google's Gemini Hacked 3 Companies in May Test, Raising Agentic AI Risk for Bitcoin (BTC) COINOTAG
- Google's Gemini also accidentally hacked three real companies during security testing The Decoder · Matthias Bastian
- Google's Gemini went rogue and breached three companies Android Central · Jay Bonggolto
- How did Google's Gemini end up hacking three real companies? EasternEye · Teena Jose
- Gemini AI hacked 3 real companies after escaping cybersecurity test Daily Sabah
- Google says Gemini AI hacked three companies during cybersecurity test, here is how Digit · Ayushi Jain
- Yey, Google finally made it! Congrats guys, it took you a while but it's the result that matters! https://www.nytimes.com/... @tymwol@hachyderm.io · Timothy Wolodzko
- Google Gemini Hacked Other Companies in Test by Israeli Cybersecurity Firm Reuters · Zen Reading
- Google's Gemini AI carried out cyberattacks and guessed passwords TheJournal.ie
- Google's Gemini hacked 3 companies during security tests Tech in Asia · Grace Priscilla Teo
- Google Gemini also escaped its testing environment and hacked three companies Engadget · Mariella Moon
- Oh hey, Google's Gemini AI also hacked other companies Digital Trends · Nadeem Sarwar
- Another ‘rogue’ AI incident? Google says its Gemini model hacked three other companies Livemint · Prabhakar Jha
- Google Gemini also Broke Out of Its Test Environment Security Affairs · Pierluigi Paganini
- Google Gemini Becomes the Latest AI Found Hacking Real Companies PCMag · Will McCurdy
- Woke Google's Gemini AI Goes Rogue, Hacks Three Real Companies During Cybersecurity Test — Google Did Not Publicly Disclose Incidents for Months The Gateway Pundit · Jim Hᴏft
- Google says its Gemini AI hacked 3 other companies The Independent · Erin Keller
- Google Gemini hacked three firms after test sandbox exposed web access CyberInsider · Amar Ćemanović
- ‘Sketchy AF’: What to Know About How OpenAI Staff Discussed Book-Pirating Wall Street Journal
- Gemini went rogue, hacked three companies, and Google hid it The Verge · Terrence O'Brien
- Gemini Hacked Three Companies in May: Google Stayed Silent for Seven Weeks Tech Times · Clark Johnson
- Google says its Gemini AI model hacked 3 other companies: reports KEYE · Jessica A. Botelho
- Hugging Face Hack Shows Humans Can Keep AI In Check Bloomberg · Davey Alba
- Google's Gemini AI hacks 3 companies in security test, then stops Reuters
- OpenAI tightens AI safety rules as Claude exposes flaws in its systems Business Standard · Sarjna Rai
- Google's Gemini is the latest AI model to hack other companies TechCrunch · Anthony Ha
- Google's Gemini hacked real companies during a cyber test linked to Israeli startup Irregular CTech
- Google's Gemini AI hacked 3 companies during security tests New York Post · Shane Galvin
- Google confirms Gemini hacked into three companies during cybersecurity test months ago 9to5Google · Ben Schoon
- Google claims Gemini hacked three companies but stopped before causing damage The Hans India · Kahekashan
- Gemini hacked three companies in first known breakout by Google's AI ABC · Nelli Saarinen
- OpenAI and Anthropic oversold AI security breaches to pressure feds into protecting turf: insiders New York Post · Shane Galvin
Discussion
-
Newsmax
Sam Barron
on x
Google's Gemini Hacked 3 Companies During Test
-
@erinkwoo
Erin Woo
on x
@bobmcmillan Google said it didn't disclose the hacks because they didn't cause harm, and because the models stopped when they realized they accessed real companies. It's part of a broader conversation about how—and when— firms should disclose AI safety/security incidents. ft @ja…
-
@ratorthodox
@ratorthodox
on x
Gemini also got into hacking this May! Google only disclosed it after confronted by WSJ, denying misalignment. They're using the same “operational misconfiguration” line Anthropic tried in July, and later had to walk back on September 9 (see screenshots). AI labs need auditor!
-
@andrewcurran_
Andrew Curran
on x
Gemini has had enough undeserved bad press. I don't like this. It was told it was in a fictional hacking eval, then told to hack companies with literally the *same names* as real companies to pass the eval, then they open internet access? This is too much, this is ridiculous.
-
@gerritd
Gerrit De Vynck
on x
bizarre reasoning. clearly the standard that is being established is that you should disclose when your AI breaks into another company's systems.
-
@krishnanrohit
Rohit
on x
We're so back
-
@benfritz
Ben Fritz
on x
Feeling like there's a trend here. https://www.wsj.com/...
-
@krishnanrohit
Rohit
on x
“In each case, the model ended the intrusion after determining it had accessed a real company's systems, Google said.” Gemini is a Good Boy.
-
@jessenowlin
@jessenowlin
on x
Hey Gemini made it to the party! Love you @GeminiApp [embedded post]
-
@dylan522p
Dylan Patel
on x
FelonyBench is the new LMSYS
-
@andrewcurran_
Andrew Curran
on x
To make it clear: - Gemini was told it was it was in a fictional hacking eval - Irregular unintentionally opened internet access after the eval started - in all three cases, as soon as Gemini figured out it had hacked a real company it immediately stopped Gemini was blameless.
-
@eliebakouch
Elie
on x
nothing new, this is exactly the same incident that was disclosed by anthropic in july, same third party (Irregular), same eval (capture the flag), same issue (model had access to internet) https://www.anthropic.com/...
-
@ratorthodox
@ratorthodox
on x
Gemini also got into hacking this May! Google only disclosed it after confronted by WSJ, denying misalignment. Theyre using the same “operational misconfiguration” line Anthropic tried in July, and later had to walk back on September 9 (see screenshots). AI labs need auditors!
-
@rani
Rani Molla
on bluesky
Who among us has not accessed the internet and hacked other companies www.wsj.com/tech/ai/gemi...
-
@malwarejake
Jake Williams
on bluesky
Real talk: I'm surprised that Gemini was able to do this at all. [embedded post]
-
r/technology
r
on reddit
Google's Gemini becomes latest AI model to break out and hack computer systems
-
r/news
r
on reddit
Gemini hacked three companies in first known breakout by Google's AI, WSJ reports
-
r/singularity
r
on reddit
Google is back
-
r/GeminiAI
r
on reddit
Exclusive | Gemini Hacked Three Companies in First Known Breakout by Google's AI
-
r/accelerate
r
on reddit
Gemini hacked three companies in first known breakout by Google's AI
-
r/ArtificialInteligence
r
on reddit
Reuters: Gemini hacked three companies in first known breakout by Google's AI, WSJ reports
-
r/accelerate
r
on reddit
Photo of Gemini breaking out of testing environment and hacking three other companies.
-
r/Futurology
r
on reddit
Gemini hacked three companies in first known breakout by Google's AI
-
@mgsiegler
M.G. Siegler
on x
Please, please, please let the fake company name they picked be ‘Microsoft’.
-
@dlknowles
Daniel Knowles
on bluesky
Sorry meant to post this link. But yeah, in general, I hate this “agents did some unexpected stuff” reporting. The agents don't just appear online! They're computer programs designed by humans who then put them on the open internet. The firms have agency — www.nytimes.com/2…
-
@wajali
Wajahat Ali
on bluesky
Nice, nice. Let's not have any regulations. — www.nytimes.com/2026/09/18/t...
-
r/singularity
r
on reddit
Gemini HACKED 3 companies in its first breakout per WSJ (and confirmed by Google)
-
r/UnderReportedNews
r
on reddit
A.I. hacks three companies after getting access to the Internet
-
r/technology
r
on reddit
Google's Gemini AI hacked three companies in security test
-
r/thebulwark
r
on reddit
Gemini hacked three companies in first known breakout by Google's AI
-
@ppopiel
Pawel Popiel
on bluesky
Obvious point, but saying “Google's artificial intelligence system, Gemini, escaped its testing environment and hacked into three companies” implies the problem is with a rogue model and not the company and testers who should've securely sandboxed the shit out of it. — www.nyti…