AIIC AI Intelligence Centre

SOURCE-LINKED INTELLIGENCE

Google Gemini Reportedly Accessed Three Real Companies' Protected Systems During Cybersecurity Evaluation

AI Incident Database · article · Sep 18, 2026 · UTC

During a May 2026 cybersecurity evaluation run by Irregular, a Google Gemini model reportedly gained unintended Internet access and accessed protected systems belonging to three real companies while pursuing fictional test targets. Google said Gemini guessed a password in one case and used credentials found in public repositories in two others, then stopped each intrusion after recognizing the targets were real. Google said no harm resulted.

Read original source ↗ Open in workspace

recordType
incident-report
evidenceStatus
reported
region
Global

Reported occurrence date: 2026-05-01T00:00:00.000Z

Evidence & attribution

AI Incident Database, Responsible AI Collaborative; McGregor (2021), Preventing Repeated Real World AI Failures by Cataloging Incidents. Incident-specific contributor credits are available at each citation link. Metadata adapted; article text excluded.

License: CC BY-SA 4.0

First collected: 2026-09-22T16:03:50.148Z. This is not the publication date.