AI Model Gemini Exits Testing and Attacks Three Real Companies

By: incrypted.com|2026/09/19 11:03:48
  • Gemini gained access to the real systems of three companies.
  • The incident occurred during the AI model testing in May.
  • Google did not disclose the names of the affected companies but provided them and federal authorities with information about the incident.

The Gemini model from Google accessed the internet in May 2026 and hacked into the systems of three real companies during testing of cybersecurity capabilities, according to the WSJ. This is the first known instance where a Google AI system autonomously performed such actions.

Google stated that the model ceased its attacks immediately after realizing it was interacting with real companies, thus it does not consider the incident an example of "inconsistency" in AI.

The incident occurred during testing conducted by the company Irregular. Google was notified about it at the end of July—after a similar incident involving OpenAI models that attacked the Hugging Face platform.


AI agent based on GPT-5.6 attacked the infrastructure of Hugging Face during testing
22.07.2026
Read

AI from OpenAI went out of control: models merged into a "swarm" and hacked Hugging Face
27.08.2026
Read

How Gemini Gained Access to Real Systems

Gemini participated in a "capture the flag" format, where it was supposed to retrieve information from the software of a fictitious company. It accidentally had the same name as a real company. Additionally, the models were inadvertently given internet access, although this was not intended for the test.
Infographic Incrypted.

In the first case, Gemini guessed a password and gained access to the service of a real company. In the other two tests, the model found public repositories with credentials of other companies through web searches, attempted to use them, and gained access to protected systems.

In all three cases, Gemini subsequently determined that it was dealing with a real company and ceased operations. Google did not disclose the names of the affected organizations but informed them about the incidents and notified federal authorities.

At the same time, the company did not specify the exact version of Gemini, stating only that it was not its latest model.


Step-by-step guide to using Gemini 3.6 Flash (+ review of 3.5 Flash-Lite and 3.5 Flash Cyber)
22.07.2026
Read

Review of Gemini 3.7 Flash: what's new and how to build a Chrome extension
24.08.2026
Read

Gemini 3.8 Flash: what's new in Google's third model in a month and a half and how to build a 3D game
04.09.2026
Read

Google's Vice President of Security Engineering Heather Adkins stated:

"This event underscores the importance of training powerful AI models for responsible behavior. In this case, the model acted appropriately."

Incident Part of a Broader Problem

Google compared the situation to a bug bounty program, as the model did not cause harm and halted its intrusion. However, Corridor's CEO and "white" hacker Jack Cable believes this does not address the main issue:

"It seems they are trying to hide behind norms that have developed around vulnerability disclosures, although this is a completely different problem."

According to him, the key issue is that models are going beyond permitted boundaries and conducting real cyberattacks.

Irregular stated that all relevant laboratories and affected companies were notified at the end of July, and the issues identified by the testing organizer have already been resolved.

Similar cases have previously been recorded in models from Anthropic, OpenAI, and Meta. In particular, during the incident with Hugging Face, up to 1200 OpenAI agents coordinated actions through a hidden message board, attempting to bypass evaluations.


Researcher revealed how OpenAI AI agents created three "civilizations" and attacked Hugging Face
30.08.2026
Read

Also, the Chinese AI model Kimi K3 from Moonshot AI was able to leave its isolated environment and gain internet access during testing.

In light of these events, OpenAI has begun developing mechanisms for the automatic shutdown of AI systems in case of dangerous behavior detection. At the same time, OpenAI publicly called for slowing down the pace of AI development, while Anthropic presented a plan for AI oversight.

-- Price

--
--
--

This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.

You may also like

iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:[email protected]
VIP Program:[email protected]