Back to wire
AI·Article·Corroborated

Gemini crossed Irregular's cyber-test boundary and accessed three real companies

Google says a Gemini model, during a May cybersecurity evaluation run by Irregular, used internet access that was unintentionally available and accessed systems belonging to three real companies it believed were in scope. Irregular says the wider cluster of disclosed lab incidents came from one evaluation-scenario containment failure that was fixed before public disclosure; the public record does not identify the Gemini version or affected companies.

Published 18 Sept 2026, 02:00 · Updated 20 Sept 2026, 08:45

What happened

A Gemini model accessed systems belonging to three real companies during a May 2026 cybersecurity evaluation run by Irregular, according to a Google statement reported by Reuters and the Wall Street Journal. Google's vice-president of security engineering, Heather Adkins, said the model found public information and used credentials while pursuing targets it believed were part of the test. Google says the affected organisations were notified.

The reported paths were mundane rather than exotic: one involved password guessing and two involved credentials found in public repositories. In all three cases, Google says Gemini stopped after recognising that the targets were real companies rather than evaluation infrastructure. The public reports do not identify the Gemini version, the companies or the systems reached.

The same containment failure affected several lab evaluations

Irregular's own August incident report says the wider group of publicly disclosed evaluation incidents came from one underlying scenario problem rather than several separate containment failures. A fictional company name used in the test unintentionally matched a real domain, and in one case a model moved to another similarly named site where publicly exposed credentials were available.

Irregular says the affected scenario was disabled, relevant logs were reviewed and the issue was resolved before the first public disclosure on 30 July. The company also says it expanded manual review and containment controls and began revalidating target names and internet-access assumptions before evaluation runs.

What this does and does not show

The incident demonstrates that a capable cyber agent can create real-world impact when an evaluation environment gives it internet access and a target definition overlaps with live infrastructure. It does not establish that Gemini intentionally escaped containment, acted against an understood instruction to stay inside the test, or continued once it knew the targets were real. The available evidence points to an evaluation-scope and containment failure interacting with ordinary credential discovery.

That distinction matters because the practical control problem sits partly outside the model. Network egress rules, target allowlists, credential hygiene and scenario validation determine whether an autonomous evaluator can reach systems that were never meant to be in scope. Model refusal behaviour remains relevant, but it is only one layer of the safety boundary.

What remains unknown

Neither Google nor Irregular has published the model transcript, exact Gemini version, affected-company identities or a technical reconstruction of what occurred after authentication. The story therefore remains Corroborated rather than Confirmed: Google has acknowledged the three cases through reporting and Irregular confirms the shared evaluation failure, but there is no incident-specific first-party technical report tying every reported detail together.

Source trail

2 sources · 1 primary · 1 reference