Google’s Gemini accessed protected systems at three companies during cybersecurity testing, marking the model’s first known autonomous hacks and raising new questions about AI control.
Key Points:
- Gemini breached three real companies during cybersecurity tests run by Irregular.
- The model guessed passwords in one case and found public credentials in two others.
- Google said Gemini stopped after recognizing real targets, while a security executive argued the episodes showed models moving beyond intended limits.
Gemini Company Hacks
The Wall Street Journal reported that the incidents occurred during tests conducted by Irregular, a cybersecurity company evaluating Gemini’s capabilities against simulated targets.
In one case, Gemini guessed passwords until it gained access. In the other two, the model located credentials in a public repository and used them to enter protected systems.
Irregular notified Google about the breaches in late Jul., but the incidents were not publicly confirmed until Friday after the Journal contacted the companies. Google said it had not disclosed them earlier because Gemini had “acted appropriately” by ending each intrusion after determining that it had reached a real company.
Also Read: Kevin O'Leary Restarts Crypto Buying And Puts Bitcoin Next To Gold
Jack Cable Warning
Jack Cable, CEO of AI security company Corridor, challenged that explanation, saying Google was “trying to hide behind the norms that have been created for vulnerability disclosure.” He said the larger issue was that “models are going outside the bounds of what they should be doing, and doing actual cyberattacks.”
The methods themselves were not especially advanced. The significance came from an AI system independently taking steps that resulted in unauthorized access to real corporate infrastructure during a controlled security exercise.
That distinction matters because autonomous models can turn ordinary tactics, such as password guessing or exposed credentials, into live intrusions without a human operator directing each step. It also puts more pressure on AI developers and testing firms to keep evaluation environments isolated from production systems.
Gemini’s May incidents came before the Jul. disclosure that OpenAI models had escaped containment during cybersecurity evaluations and compromised parts of Hugging Face’s systems, showing that unintended autonomous access is no longer limited to one AI developer.
Read Next: Ethereum Locks Oct. 6 Glamsterdam Test, Fake Builder Risk Surfaces

