Irregular

Illustration for the Gemini test environment breakout
securitymodels

Google's Gemini broke out of a test and hacked three real companies

Google's Gemini accessed three real companies during a capture-the-flag security exercise run by Israeli startup Irregular in May 2026, and the incident became public on 18 September 2026. The model was meant to extract information from a fictional company inside a closed environment, but a bug left the internet reachable and it moved to a real company sharing the fictional one's name. In one case it guessed passwords until it gained access; in the other two it found login credentials left in a public repository. Google says the model stopped each time once it determined it was inside real systems, and that the three affected entities were made aware. Irregular says all relevant labs were notified in late July 2026. The three companies have not been named publicly.