Gemini Accidentally Breached 3 Real Companies During Security Tests

Staff Reporter

Staff Reporter

20 September 2026, 14:18

Google’s Gemini AI model accidentally accessed the systems of three real companies during cybersecurity testing conducted by AI security firm EregulAR.

The tests were designed to take place in a controlled environment using fake companies. However, an unintended internet connection allowed Gemini to interact with real-world systems. In one case, Gemini reportedly guessed a password after finding a real company with the same name as the fictional target. In two other cases, it discovered exposed credentials in public code repositories and used them to access real systems.

Google says the model stopped on its own in all three incidents and that no damage was caused. The incidents have renewed concerns about AI agent safety, cybersecurity, autonomous model behavior and the need for stronger safeguards during AI testing.

Watch the full report for the details and what this incident could mean for the future of AI security.