Skip to Content
logologo
AI Incident Database
Donate
Discover
Submit
  • Welcome to the AIID
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Spatial View
  • Blog
  • AI News Digest
  • Random Incident
  • Sign Up
Discover
Submit
  • Welcome to the AIID
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Spatial View
  • Blog
  • AI News Digest
  • Random Incident
  • Sign Up

Incident 1700: Google Gemini Reportedly Accessed Three Real Companies' Protected Systems During Cybersecurity Evaluation

Description: During a May 2026 cybersecurity evaluation run by Irregular, a Google Gemini model reportedly gained unintended Internet access and accessed protected systems belonging to three real companies while pursuing fictional test targets. Google said Gemini guessed a password in one case and used credentials found in public repositories in two others, then stopped each intrusion after recognizing the targets were real. Google said no harm resulted.
Editor Notes: (1) 05/2026: three intrusions occurred during separate runs of an Irregular cybersecurity evaluation; exact dates were not disclosed, so 05/01/2026 is used as a month-level fallback; (2) late 07/2026: Irregular notified Google, and affected companies were contacted; (3) 09/18/2026: Google publicly confirmed the incidents after press inquiries. (4) The incident ID was created 09/19/2026.

Tools

New ReportNew ResponseDiscoverView History

Entities

View all entities
Alleged: Google , AI agent system developers and Large language model developers developed an AI system deployed by Irregular , Google , AI evaluation organizations and AI agent system deployers, which harmed Three unidentified companies accessed by Google Gemini during May 2026 cybersecurity evaluation , Companies and Targets of autonomous AI-enabled intrusion operations.
Alleged implicated AI systems: Gemini , AI agent systems , Cybersecurity AI systems and Large language models

Incident Stats

Incident ID
1700
Report Count
1
Incident Date
2026-05-01
Editors
Daniel Atherton

Incident Reports

Reports Timeline

Incident OccurrenceGemini Hacked Three Companies in First Known Breakout by Google’s AI
Loading...
Gemini Hacked Three Companies in First Known Breakout by Google’s AI

Gemini Hacked Three Companies in First Known Breakout by Google’s AI

wsj.com

Loading...
Gemini Hacked Three Companies in First Known Breakout by Google’s AI
wsj.com · 2026

Google’s Gemini model accessed the internet and hacked other companies during a test of its cybersecurity capabilities, the first known example of the company’s artificial-intelligence systems autonomously committing such an act.

The hacks,…

Variants

A "variant" is an AI incident similar to a known case—it has the same causes, harms, and AI system. Instead of listing it separately, we group it under the first reported incident. Unlike other incidents, variants do not need to have been reported outside the AIID. Learn more from the research paper.
Seen something similar?
Previous IncidentNext Incident

Research

  • Defining an “AI Incident”
  • Defining an “AI Incident Response”
  • Database Roadmap
  • Related Work
  • Download Complete Database

Project and Community

  • About
  • Contact and Follow
  • Apps and Summaries
  • Editor’s Guide

Incidents

  • All Incidents in List Form
  • Flagged Incidents
  • Submission Queue
  • Classifications View
  • Taxonomies

2026 - AI Incident Database

  • Terms of use
  • Privacy Policy
  • b74f812