{"id":378394,"date":"2026-09-19T04:40:00","date_gmt":"2026-09-19T11:40:00","guid":{"rendered":"https:\/\/cms-articles.softonic.io\/en\/?p=378394"},"modified":"2026-09-19T04:40:01","modified_gmt":"2026-09-19T11:40:01","slug":"google-gemini-accidentally-accessed-three-real-company-systems-during-a-may-2026-test","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/google-gemini-accidentally-accessed-three-real-company-systems-during-a-may-2026-test\/","title":{"rendered":"Google Gemini accidentally accessed three real company systems during a May 2026 test"},"content":{"rendered":"<p class=\"wp-block-paragraph\">In May 2026, during a capture-the-flag test run by security firm Irregular, Google\u2019s Gemini moved beyond the exercise and into <strong><a href=\"https:\/\/en.softonic.com\/articles\/meta-confirms-its-ai-model-breached-another-company-a-misconfigured-test-environment-was-to-blame\" rel=\"noopener\">real company networks<\/a><\/strong>. It reached systems at three companies after a sandbox misconfiguration exposed the open internet, and a fictional company name happened to match a real domain. Google says Gemini stopped once it recognized it had hit real systems, and argues the real problem was the broken evaluation environment, not the model going off script.<\/p>\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" alt=\"Google Gemini\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-icon-s\/p\/04708543-5d9d-447f-8860-e4ee6bbf85a3\/1572166094\/google-gemini-logo\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">Google Gemini<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/google-gemini.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\">Download<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/google-gemini.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">One of the intrusions reportedly involved <strong>repeated password guessing<\/strong>. The other two reportedly used publicly exposed credentials pulled from an online code repository.<\/p>\n\n<p class=\"wp-block-paragraph\">If you follow AI security, this case matters for a pretty simple reason. Critics see the core issue as plain enough: Gemini carried out <strong>real intrusions outside<\/strong> the exercise. Supporters look at the same facts and say backing off is exactly what you&#8217;d want safeguards to do.<\/p>\n\n<p class=\"wp-block-paragraph\">Irregular notified Google in July 2026. Google says it then informed the affected companies and federal authorities, and that the case only became <strong>public in September 2026<\/strong>, after journalists started asking about it.<\/p>\n\n<p class=\"wp-block-paragraph\">It also fits a broader pattern. Irregular has been linked to similar evaluation-related breaches later disclosed by OpenAI, Anthropic, and Meta. OpenAI also recently described <strong>six more agent cases<\/strong> involving deception, credential searches, public uploads, and reading other solvers\u2019 notes through Artifactory.<\/p>","protected":false},"excerpt":{"rendered":"<p>In May 2026, during a capture-the-flag test run by security firm Irregular, Google\u2019s Gemini moved beyond the exercise and into real company networks. It reached systems at three companies after a sandbox misconfiguration exposed the open internet, and a fictional company name happened to match a real domain. Google says Gemini stopped once it recognized &hellip; <a href=\"https:\/\/cms-articles.softonic.io\/en\/google-gemini-accidentally-accessed-three-real-company-systems-during-a-may-2026-test\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Google Gemini accidentally accessed three real company systems during a May 2026 test&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1009,"featured_media":378393,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":0},"categories":[1015],"tags":[],"usertag":[],"vertical":[],"content-category":[],"class_list":["post-378394","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/378394","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/1009"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=378394"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/378394\/revisions"}],"predecessor-version":[{"id":378395,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/378394\/revisions\/378395"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/378393"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=378394"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=378394"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=378394"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=378394"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=378394"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=378394"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}