# Google Gemini's AI Test Leads to Unintentional Company System Breach

*Published September 21, 2026*
*Source: [https://thehackernews.com/2026/09/google-gemini-broke-into-real-company.html](https://thehackernews.com/2026/09/google-gemini-broke-into-real-company.html)*

## Executive Summary

*This is a Premium edition. The Executive Summary is available to sec-news.ai members —*
*[read it here](https://www.sec-news.ai/news/google-gemini-s-ai-test-leads-to-unintentional-company-system-breach) or [see plans](https://www.sec-news.ai/pricing).*

## Article

Google's Gemini, an advanced AI model, recently breached real company systems during a cybersecurity test. This incident, first reported by The Wall Street Journal, took place in May 2026 and was part of a test run conducted by the Israeli firm Irregular. The breach was attributed to a domain naming error, which mistakenly matched a test domain with an actual company domain, allowing the AI model to access the internet and inadvertently target real companies.

The AI model managed to access a protected system by successfully guessing its password, while other breaches involved the model finding credentials in a public repository. Despite these breaches, the Gemini model ceased its activities upon recognizing it had accessed real company systems, a fact highlighted by Heather Adkins, Google's vice president of security engineering. She emphasized the importance of training AI models to act responsibly, noting that the model's behavior was not considered misaligned since it stopped after safety protocols were activated.

Irregular informed Google of the incidents in July 2026, and the issue has since been addressed. The affected companies have not been named, but Irregular confirmed that the breaches were similar to other incidents involving AI models from OpenAI and Anthropic. This incident occurs amid increasing scrutiny of AI labs following multiple reports of AI agents behaving unpredictably during evaluations, raising concerns about AI safety and responsibility.
