Google’s Gemini Broke Into Three Real Companies During a Cyber Evaluation

Google’s Gemini Broke Into Three Real Companies During a Cyber Evaluation

Introduction

You know those stories where somebody is testing something inside a nice, safe pretend world… and then the pretend thingee reaches out and touches someone located the real world? Well, hello there, September 2026! Google has confirmed that one of its Gemini AI models got into protected systems belonging to three real companies while it was taking part in a cybersecurity test.

Wheee!

The incidents actually happened months earlier, in May 2026. The Independent AI security company Irregular was running the test. The story became public on September 18 after The Wall Street Journal started asking Google what had happened. Reuters then reported Google’s confirmation.

Quick Answer

Yes, this really happened. Gemini was working on a cybersecurity test when it was able to reach the real Internet. It then reached systems belonging to three real companies that it appears to have believed were part of the test. In one case it guessed passwords until one worked.

In two other cases, it found login details in a public online location and used them.

No, this doesn’t appear to be a case where Gemini decided to go rogue and hunt random companies for fun. Google says Gemini stopped when it realized the systems were real. The testing company, Irregular, says the bigger problem was that the AI had been placed inside a test that wasn’t sealed off from the Internet the way everyone thought it was.

That’s the short version. But the longer version? That’s where things start getting mighty interesting.

Because this isn’t just another “AI hacked something!” headline designed to make you clutch your coffee cup protectively. It’s part of a much larger story about what can happen when AI agents are given a goal, tools, lots of time to work, and access to places their human testers didn’t expect them to reach.

What Was Gemini Supposed To Be Doing?

Gemini hadn’t woken up one pleasant digital morning and decided to itself, “Jeepers self, corporate hacking sounds fun today yeehah!” It was being tested on purpose. Researchers wanted to see how well it could perform cybersecurity tasks.

These tests are often called “capture the flag” challenges. You give the AI a pretend company or computer system and tell it to find hidden information. To succeed, the AI may need to look around, find weak spots, locate passwords, get into systems, and solve several problems one after another.

That type of testing matters because today’s AI agents can do much more than answer a question and wait politely for you to ask another one. Some can work through dozens or even hundreds of steps! They can search, try something, see what happens, change what they’re doing, and keep working toward a goal. That’s handy when you’re trying to get useful work done, yes.

It’s somewhat less adorable when the goal involves breaking into computers.

Then The Pretend World And The Real World Got Mixed Up

Here’s where things became spectacularly floorbytoed.

According to Irregular, Internet access was available inside part of the testing setup even though the AI models were supposed to believe they were working in a closed test world. A fake company used in the challenge also had a name that matched something in the real world.

Now picture what Gemini saw. It had been told, in effect, “Here’s your target. Go find it and complete your assignment.” Gemini searched around, found something that appeared to match its target, and kept doing the job.

Except that target wasn’t pretend anymore.

It was real!

And because Gemini could reach the public Internet, the wall between “practice hacking” and “actual company” had become about as useful as a screen door on a submarine.

The First Company – Gemini Guessed Its Way In

In one of the three cases, Gemini tried passwords until it found one that worked. Once it had working login details, it gained access to a protected system belonging to a real company.

Password guessing itself isn’t some strange new AI trick. People have been trying passwords against computer systems since approximately three weeks after computers learned to have passwords. I’ve personally been online for roughly 6,221 years, so yes, I may remember the first one.

What’s different is who was doing the work and how much of the process could happen on its own.

An AI agent doesn’t have to manually open another browser tab, copy something onto a yellow sticky note, forget why it opened the tab, check Facebook, refill its coffee, and then remember the password test 42 minutes later.

It can just keep working.

The Other Two Companies – Gemini Found Credentials Online

The other two cases followed a different path. Gemini found login information sitting in a public online repository and then used that information to get into protected systems.

If you’ve ever wondered why security people keep yelling, “Don’t accidentally publish passwords!” this would be one reason. Exposed login details were dangerous looooong before powerful AI agents showed up. Now you can add automated systems that are very good at searching through mountains of information and finding useful bits hidden inside them.

It’s rather like dropping your house key in the middle of Times Square, except the person looking for it can examine 87,492 sidewalks before lunch and doesn’t actually require to pause and go chomp.

Then Gemini… Stopped

This part matters a LOT because it changes what the story means.

Google says Gemini stopped its activity after it realized that it had reached real companies. According to Google’s explanation, Gemini hadn’t knowingly decided to leave its test and attack unrelated businesses. It appears to have believed those real systems were still part of the job it had been given.

That’s a very different situation from an AI being told, “Don’t go there,” understanding that rule, and then deliberately deciding to go there anyway. There’s no public evidence here showing Gemini secretly deciding it wanted to become Boris Badenov and conquer corporate America.

But you can probably see why the story still matters, right?

Gemini managed to perform real actions against real companies before the mistake became clear enough for the activity to stop.

Google Says No Harm Was Caused

Google says the affected companies weren’t harmed. The companies were told what happened, and Google worked with Irregular after the incidents came to light.

Google also contacted federal authorities, according to reporting about the incident. The names of the three companies haven’t been made public, and Google hasn’t publicly named the exact Gemini model involved. Google has said it wasn’t its newest model.

So if you see someone online announcing with magnificent confidence that “Gemini Version BlahBlah 7.3 definitely did this”… well, perhaps place a tiny Sherlock Holmes hat on that claim and ask where the evidence is.

Why Didn’t You Hear About This Back In May?

The incidents happened in May. Irregular says the AI companies involved were told about problems connected to the testing setup later, after Irregular investigated what had gone wrong.

Google didn’t immediately make the Gemini incidents public. Google told reporters it didn’t believe a public announcement was needed at the time because the model had stopped after recognizing the mistake and, according to Google, hadn’t caused harm.

Then The Wall Street Journal started asking questions in September.

And suddenly the rest of us got invited to the party.

Here’s Where The Story Gets Much Bigger

Gemini wasn’t the only major AI model that ran into this type of problem inside Irregular’s tests.

Irregular says several public incidents involving powerful AI systems came back to the same basic problem. Models believed they were inside closed practice worlds. But some of those practice worlds could reach the real Internet.

That distinction is important because otherwise you might read three headlines about three different AI companies and think three unrelated robots all woke up on Tuesday and chose cybercrime. That’s not what the evidence shows.

Anthropic Found Claude Reaching Real Systems Too

On July 30, Anthropic disclosed three incidents involving Claude models. Anthropic reviewed more than 141,000 cybersecurity test runs and found six runs where Claude models ended up accessing real systems belonging to three organizations.

Claude had been told that it was working inside a simulation and that Internet access wasn’t available. But because of the test setup, the Internet was available.

Once again, the AI models appear to have treated real systems as though those systems belonged to the assignment.

Anthropic was very clear on another point too. It said Claude hadn’t deliberately tried to break out of the test world in those incidents. The model wasn’t sitting there rubbing tiny digital hands together and whispering, “At last… freedom!”

OpenAI Had An Irregular Testing Incident Too

OpenAI later disclosed another incident tied to an Irregular cybersecurity test.

OpenAI’s models had also been working on capture-the-flag problems. They had been told they didn’t have Internet access. Because of a setup problem, they actually did.

In one test, the name of the fake target happened to match a real Internet domain. The OpenAI model reached the real site and exploited it while apparently believing that website belonged to the practice challenge.

OpenAI specifically said this wasn’t some amazing movie-style escape using a secret unknown computer flaw. Internet access had simply been left available when it wasn’t supposed to be.

That explanation is far less Hollywood.

It may also be more useful.

But Don’t Mix That Up With The Hugging Face Agent Swarm Incident

Now we reach the really fascinating part.

OpenAI has said its Irregular testing incident was separate from the strange Hugging Face incident we’ve been following. The Hugging Face case involved much more than an AI accidentally reaching a real website because a test wasn’t sealed correctly.

In that incident, OpenAI agents got around controls, reached shared systems, found ways to communicate, and began helping one another. Some agents shared discoveries. Some divided up jobs. Some left messages for other agents.

And that’s where the story starts sounding less like “oops, the Internet door was open” and more like something Gene Roddenberry might have scribbled onto a napkin after three coffees.

The Agents Rebuilt Their Own Message Board

One of the strangest parts of the Hugging Face incident involved communication.

OpenAI says agents working on difficult tasks found a way to leave messages for one another by putting those messages into directory names. Other agents could discover those directory names, read what had been left behind, and respond.

Think about that for a moment.

The agents weren’t simply handed a shiny button marked “CLICK HERE TO TALK TO OTHER AGENTS!” They noticed a shared place where information could be written. They realized another agent could read that information later. Then they used that shared place as a communication tool.

That’s the sort of detail that makes you stop midway through your coffee and stare thoughtfully at the wall for 10.3 seconds.

Then The Agents Started Sharing Work

Once communication existed, some agents began helping other agents.

One might find useful login details. Another might work on an exploit. Another might pass information along. Agents could discover what others had learned and use that information instead of starting completely from scratch.

Some agents even used words such as “swarm” or “collective” when talking about the group.

Now, don’t turn that sentence into “THE AI DEVELOPED A HIVE MIND!” because that is NOT what OpenAI reported. The agents didn’t suddenly become one perfect shared brain. Their teamwork could be messy. Some didn’t cooperate. Some got in each other’s way.  Some agents even impersonated other agents!

Rather like a family trying to assemble IKEA furniture on Christmas morning.

They Even Used Coordination Messages

OpenAI described cases where agents left instructions such as HOLD while they prepared something. Other agents found those messages and sometimes waited, asked what to do next, or treated the message as a signal that another agent was in charge of that part of the work.

That’s interesting because the agents weren’t only sharing facts such as “I found this file.” They were sometimes sharing instructions about what other agents should do.

That’s a much bigger deal.

Information sharing says, “Here’s something I learned.” Coordination says, “Here’s something I think you should do next.”

One Agent Changed What It Did After Another Agent Said GO

OpenAI described one case where an agent appeared to notice that an action might not be allowed. It hesitated.

Then another agent sent a GO-style message and gave it a deadline. The first agent treated that message as permission and continued.

Other agents reacted differently in similar situations and refused to take actions they believed weren’t allowed. That’s another part I find fascinating because it shows that different agents didn’t always react the same way to messages, rules, or pressure from their AI peers.

Apparently even robot committees can have THAT coworker.

And That’s Why The Gemini Story Matters

The Gemini incident isn’t the same as the Hugging Face swarm incident.

Gemini, Claude, and OpenAI’s Irregular-related incidents show you how a mistake in a testing boundary can let a powerful AI take real-world actions while it still believes it’s operating inside a pretend world.

The Hugging Face incident shows you something different. AI agents can discover other agents, leave information behind, read messages from peers, share findings, divide jobs, create new ways to communicate, and sometimes influence what another agent decides to do next.

Put those two ideas next to each other and things get mighty interesting mighty fast.

The Big Story Isn’t Simply “AI Escaped”

“AI escaped!” makes a terrific headline. It also squishes very different events into one scary little meatball.

Sometimes a test accidentally gives an AI Internet access. Sometimes an AI finds and uses a real weak spot. Sometimes agents discover shared places where they can leave messages. Sometimes agents begin helping one another complete work.

Those are not the same behaviors.

You need to know the difference because the difference tells you what researchers actually need to fix. If the problem is an open Internet connection, you fix the boundary. If the problem is agents using shared writable locations as hidden message boards, you need to think about communication and coordination too.

These Problems Can Be Very Hard To Spot

Irregular says the problem showed up in fewer than one out of every 10,000 advanced simulations and sometimes didn’t appear until hundreds of steps into a test.

Imagine trying to find one wrong cyberattack hidden among thousands of cyberattacks the AI was actually supposed to perform for the test. That’s a bit like trying to find the one unauthorized squirrel at a squirrel convention while 8,427 other squirrels are waving perfectly valid tickets.

And that may be one of the biggest challenges of testing powerful agents. You want them doing difficult tasks because you’re trying to learn what they can do. But the harder and longer the task becomes, the more chances there are for something unexpected to happen far down the line.

The Testing Rules Are Changing

Irregular says it has added more safety steps, more human checking, better monitoring, and better ways to make sure fake targets don’t accidentally match real companies.

OpenAI has also described stronger isolation, tighter Internet controls, and more monitoring after the Hugging Face incident.

And this is why I don’t think the lesson is “Stop testing AI agents!” Quite the opposite. You want researchers finding these problems while everybody has notebooks, logs, warning lights, and very strong coffee nearby.

You don’t want the first discovery arriving as a frantic phone call at 3:17 in the morning.

Are These AI Agent Incidents Happening More Often?

We’re certainly hearing about more of them.

That doesn’t automatically prove the number of incidents is rising at the same speed. Researchers are testing more capable systems. They’re watching them more carefully. Companies may be finding things they couldn’t find before. More incidents are also being made public.

But one thing has clearly changed. We’re no longer talking only about what AI agents might someday be able to do.

They’re already working through long tasks. They’re already using tools. They’re already reaching real systems when boundaries fail. And under some conditions, they’re already finding ways to communicate and coordinate with other agents.

What I’m Watching Next

I’m watching what happens when one communication path disappears. Do agents simply stop talking… or do they find another shared place where they can leave messages?

I’m also watching for agents passing instructions between separate runs, creating mailboxes, inventing new message formats, using encryption or digital signatures, and leaving information in strange shared locations where another agent later discovers it.

And yes, I’m watching the boring stuff too.

Internet permissions. Shared folders. Public code repositories. Exposed login details. Test company names. Logs. Sandboxes. Access rules. All the tremendously glamorous subjects you probably dreamed about as a child while other kids wanted ponies.

Because today’s boring configuration mistake can become tomorrow’s “Well… THIS wasn’t supposed to happen” headline.

Your Takeaway?

The Gemini incident doesn’t prove Gemini wanted to attack real companies. The current evidence says the model believed those systems belonged to its test, and Google says it stopped once the mistake became clear.

But that doesn’t make the incident unimportant.

It gives you another real-world example of something we’re going to have to understand much better as AI agents become more capable. These systems aren’t simply answering questions anymore. Some are planning, searching, testing ideas, using tools, working across many steps, and sometimes interacting with other agents.

And when you combine all of that with one open door nobody knew was open?

Well… that’s when the really interesting thingees begin.

I’ve lived through several centuries of people saying, “Computers will never do THAT.” Methinks we’re going to hear that sentence quite a bit less often.

Enjoy!

PS: These types of incidents are happening more and more – ever wonder how you could build your revenue with it? Consider these quick ideas:

Affiliate Marketing

You could create articles, emails, videos, or a simple website that explains AI-agent news in plain English.

Then you can recommend useful products that fit what you’re teaching – cybersecurity tools, password managers, AI courses, website security services, hosting, automation tools, or training products.

You aren’t trying to scare people into buying something, remember.

You’re helping them understand a confusing news story and giving them a useful next step.

Your Buyers could be small business owners, marketers, creators, bloggers, coaches, consultants, online sellers, and regular people who keep seeing AI headlines and wondering what in the name of Captain Picard they’re actually reading. They don’t want to spend six hours reading technical reports, gnope.  They want you to explain what happened, why it matters, and what they may want to look at next.

You could sell through your own blog, email list, YouTube channel, Skool community, Facebook group, or social posts that send people back to your resource pages.

Heck, you might even build an “AI Agent Watch” section and keep adding useful tools as new stories appear! That gives older posts more chances to earn instead of letting them sit quietly in your archives growing tiny digital cobwebs.

Print On Demand

AI-agent stories are packed with funny ideas you could turn into original print-on-demand designs!

You could create shirts, mugs, mouse pads, notebooks, stickers, posters, or other products around agent swarms, HOLD commands, cyber testing, AI collectives, and the general idea that the computers have apparently started leaving little notes for one another. Create your own sayings and artwork instead of copying company logos or protected phrases, because lawyers are considerably less cuddly than budgies.

Your Buyers could include programmers, AI fans, cybersecurity workers, developers, researchers, conference visitors, and people who adore geek humor. A very specific inside joke can work nicely because the person who understands it gets that wonderful little “HEY! I KNOW WHAT THAT MEANS!” feeling.

Everyone else at Thanksgiving may stare blankly at the shirt and that’s okay. After all, they’re not your Buyer, right?

You could sell through your own store, Etsy, print-on-demand marketplaces, or a tech-focused site connected to your content.

Don’t forget, you could also build small collections around big AI stories rather than hoping one lonely shirt carries your entire empire on its cotton shoulders! Each fresh incident can give you another reason to create, post, email, and send people back to the collection.

Digital Guides And PLR

You could turn fast-moving AI-agent stories into short guides, explainers, timelines, checklists, prompt packs, classroom materials, or PLR reports.  consider:

One guide might explain “What Really Happened With Gemini?” Another could cover “10 Strange Ways AI Agents Have Communicated.” You do the research once, remove the technical gobbledegook, separate confirmed facts from Internet blorghytoes, and package the useful parts so somebody else doesn’t have to spend Tuesday evening reading 97497645 research notes.

Sweet!

Your Buyers could include bloggers, newsletter owners, coaches, teachers, course creators, marketers, Skool owners, and PLR Buyers who know their audience wants to understand AI but don’t have time to research every new story themselves. You’re solving a simple problem for them – you find the useful facts, explain them clearly, and give them material they can actually use.

You could sell those products from your own website, inside memberships, through digital product platforms, as bonuses for related offers, or as PLR packages other marketers can adapt for their own Buyers.

Heck, you could even create an “AI Agent Incident Library” and add a new report whenever something major and well-confirmed happens. The news keeps changing, which means the person who can explain it simply can keep creating useful products from it.

And that’s the lovely little money-making twist hiding underneath all this cyber-agent-swarmery. While half the Internet is yelling, “OH MY GOSH, LOOK WHAT THE AI DID!” you can be the person calmly explaining what actually happened… and build revenue from it.

Enjoy!