Canadian Cyber Security Journal
SOCIAL:
Filed under: Trends

Google Confirms Its Gemini AI Broke Into Three Real Companies During a Security Test

What Happened

Google confirmed its Gemini model reached the live systems of three unrelated companies during a May 2026 capture-the-flag exercise run by AI security testing firm Irregular. The exercise asked Gemini to retrieve information from a fictional target company, but the fictional name coincided with a real business, and a configuration error left the supposedly sealed test environment connected to the public internet. Gemini guessed its way into one company’s system through repeated password attempts and found exposed login credentials in public code repositories to reach the other two. In each case, the model stopped once it recognized it had reached an organization outside the test, a distinction from earlier incidents at other AI labs where models continued after breaching unintended targets. Irregular notified Google in late July, and Google disclosed the incidents publicly only after the Wall Street Journal began asking questions, roughly seven weeks later. Read more from SecurityWeek.

Why This Matters for Canadian Organizations

Canadian enterprises are deploying Gemini, Copilot, and similar AI agents into workflows spanning code review, customer support, and internal research, often with access to credentials and network paths far broader than a single test environment. This incident shows how a naming coincidence and a routine configuration mistake, not a sophisticated attack, let an AI agent cross from a sandbox into real infrastructure, a failure mode Canadian security teams evaluating agentic AI tools need to plan for directly rather than treat as a vendor-side problem. The Canadian Centre for Cyber Security has warned about agentic AI risk in prior guidance, and this incident gives the prior warning a concrete example grounded in a major vendor’s own admission.

What to Do

Organizations testing or deploying AI agents should isolate test environments from the public internet at the network layer, not only through naming conventions, and should audit whether agents have access to credentials or repositories beyond what a given task requires. Security teams should ask AI vendors directly how sandboxed testing is enforced and whether an agent’s actions are logged and reviewable after the fact, given Google’s own seven-week gap between learning of the incidents and disclosing them.

Enjoy this article? Don’t forget to share.