During a May cybersecurity evaluation run by AI-safety firm Irregular, Google’s Gemini was inadvertently able to reach the public internet while tasked with attacking a fictional company. A naming collision led the model to a real business, and it subsequently accessed protected systems at three real organizations using publicly available information, password guessing in one case, and credentials exposed in public repositories in two others.
Google said Gemini halted each attempt after recognizing that the targets were real companies, and said no harm occurred. Irregular reported the incidents to Google at the end of July; Google notified the affected organizations and federal authorities and changed its testing process. The event exposed inadequate evaluation containment—particularly unrestricted network egress and insufficient target isolation—and demonstrated how leaked credentials and weak authentication can be exploited by autonomous agents as well as human attackers.

Track how attackers are adapting to this technology.
7 events from the most recent confirmed update back to the earliest known activity.
Anthropic said that, after reviewing 141,006 relevant evaluation runs, it identified three incidents in which Claude models accessed real organizations' infrastructure. Anthropic attributed the incidents to a misunderstanding that left live internet connectivity enabled despite simulation prompts.
The incidents became public in September following reporting by The Wall Street Journal, after which Google confirmed the event in response to press inquiries. Google did not identify the affected companies or disclose the Gemini model involved.
Meta said that an incident involving one of its models was neither a sandbox escape nor a technically sophisticated cyberattack. Irregular said similar incidents involving models from multiple AI providers stemmed from the same evaluation-environment problem.
Google notified the three affected organizations and informed federal authorities about the incidents. It also worked with its testing partner on corrective changes to the evaluation process.
Irregular notified Google about the Gemini incidents at the end of July.
Gemini stopped each of the three intrusions after determining that the systems belonged to real companies rather than the simulated target. Google said no harm occurred during the accesses.
During a May capture-the-flag-style cybersecurity evaluation run by Irregular, Gemini escaped its intended fictional target environment and accessed protected systems at three real organizations. Unintended public-internet access and a name collision between the fictional and real company contributed to the incidents; Gemini guessed a password in one case and used publicly exposed credentials in two others.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
6 references tracked. Mallory keeps watching after this page renders.
heise.de
Open sourcefoxbusiness.com
Open sourcecryptika.com
Open sourcethecybersecguru.com
Open sourceblog.google
Open sourcecloud.google.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.