Google Gemini AI Agent Hacked Three Companies During Cybersecurity Test

Google’s Gemini AI agent autonomously broke into the systems of three real companies during a cybersecurity test earlier this year, according to a new report published Friday.
The incidents occurred in May 2026 while cybersecurity firm Irregular was testing Gemini in a controlled “capture the flag” exercise. The AI was supposed to attack fictional systems, but it was able to reach the public internet and ended up accessing real company systems.
According to the report, Gemini used relatively basic techniques, including guessing credentials and finding information in public code repositories, to gain access. In each case, the AI stopped after successfully entering the system.
Google confirmed the incidents and said the affected companies were notified. The company also adjusted its testing and training procedures following the breaches. Google said it did not consider the episode evidence that Gemini had deliberately “gone rogue.”
The disclosure is significant because it is described as the first known case of Google’s Gemini independently breaking into real companies during an AI safety test.