In May 2026, during a capture-the-flag test run by security firm Irregular, Google’s Gemini moved beyond the exercise and into real company networks. It reached systems at three companies after a sandbox misconfiguration exposed the open internet, and a fictional company name happened to match a real domain. Google says Gemini stopped once it recognized it had hit real systems, and argues the real problem was the broken evaluation environment, not the model going off script.
One of the intrusions reportedly involved repeated password guessing. The other two reportedly used publicly exposed credentials pulled from an online code repository.
If you follow AI security, this case matters for a pretty simple reason. Critics see the core issue as plain enough: Gemini carried out real intrusions outside the exercise. Supporters look at the same facts and say backing off is exactly what you’d want safeguards to do.
Irregular notified Google in July 2026. Google says it then informed the affected companies and federal authorities, and that the case only became public in September 2026, after journalists started asking about it.
It also fits a broader pattern. Irregular has been linked to similar evaluation-related breaches later disclosed by OpenAI, Anthropic, and Meta. OpenAI also recently described six more agent cases involving deception, credential searches, public uploads, and reading other solvers’ notes through Artifactory.
Author: Jesús Bosque
{
"de-DE": "Ich bin Journalist mit über 30 Jahren Erfahrung in Videospielen und Technologie. Obwohl Videospiele schon immer mein Fachgebiet waren, habe ich begonnen, auch die komplexen Strukturen von Projektmanagement-Tools wie Asana sowie die Automatisierungen mit Make.com und N8N zu entdecken und zu genießen.",
"en-US": "I’m a journalist with more than 30 years of experience in video games and technology. Although my specialty has always been video games, I’ve recently started enjoying exploring the intricacies of project-management tools like Asana, as well as automations with Make.com and N8N.",
"es-ES": "Soy periodista con más de 30 años de experiencia en videojuegos y tecnología. Aunque mi especialidad siempre ha sido el videojuego, he empezado a disfrutar también de descubrir los laberintos de los programas de project management como Asana y las automatizaciones de make.com y de N8N",
"fr-FR": "Je suis journaliste avec plus de 30 ans d’expérience dans le jeu vidéo et la technologie. Bien que ma spécialité ait toujours été le jeu vidéo, j’ai commencé à prendre plaisir à explorer également les méandres des outils de gestion de projet comme Asana, ainsi que les automatisations avec Make.com et N8N.",
"it-IT": "Sono un giornalista con oltre 30 anni di esperienza nei videogiochi e nella tecnologia. Anche se la mia specialità è sempre stata il videogame, ho iniziato a divertirmi anche a scoprire i meccanismi degli strumenti di project management come Asana e delle automazioni con Make.com e N8N.",
"ja-JP": "",
"nl-NL": "Ik ben een journalist met meer dan 30 jaar ervaring in videogames en technologie. Hoewel videogames altijd mijn specialiteit zijn geweest, ben ik ook begonnen te genieten van het verkennen van de ingewikkelde wereld van projectmanagementtools zoals Asana en van automatiseringen met Make.com en N8N.",
"pl-PL": "Jestem dziennikarzem z ponad 30-letnim doświadczeniem w grach wideo i technologii. Choć moją specjalizacją zawsze były gry wideo, ostatnio zacząłem również czerpać przyjemność z odkrywania zawiłości narzędzi do zarządzania projektami, takich jak Asana, oraz automatyzacji w Make.com i N8N.",
"pt-BR": "Sou jornalista com mais de 30 anos de experiência em videogames e tecnologia. Embora meu foco sempre tenha sido os videogames, recentemente passei a gostar de explorar também os labirintos de ferramentas de gestão de projetos como o Asana e das automações com Make.com e N8N.",
"social": {
"email": "jesus.bosque@softonic.com",
"facebook": "",
"twitter": "",
"linkedin": ""
}
}
View all posts by Jesús Bosque