Gemini hacked three companies but stopped before doing any harm, Google says

Direct Source Verification: This story is aggregated from India Today (indiatoday.in). Full reporting rights and copyright belong to the primary publisher.
Google has become the latest company to disclose that its AI agents hacked another company. The tech giant has confirmed that its Gemini AI models hacked into three real companies during a cybersecurity test, but the AI stopped on its own after it realised what had happened.

Google has become the latest company to disclose that its AI agents hacked another company. The tech giant has confirmed that its Gemini AI models hacked into three real companies during a cybersecurity test, but the AI stopped on its own after it realised what had happened.

As per a report from the Wall Street Journal, Google’s Gemini model accessed the internet and hacked three outside companies during a cybersecurity test run by the Israeli startup Irregular in May. This marks the first known case of the company’s AI systems autonomously carrying out such an act.

Irregular is an AI startup that has been linked to similar incidents, including the infamous OpenAI Hugging Face breach, where over 700 rogue AI agents tried to hack the US company Hugging Face’s systems.Gemini hacks three companies

According to Google, the incidents arose from a case of mistaken identity during a “capture the flag” exercise on Irregular’s infrastructure. Gemini had been tasked with retrieving information from software run by a fictional company inside the test environment, but that fictional company had the same name as a real company.

Although the model was not meant to have internet access, Irregular said internet access was unintentionally made available. This allowed Gemini to access the real company’s systems – which in one case it did by guessing passwords. But when the AI realised that it had accessed a real company, Google says, it had stopped itself and exited.

In two other runs, Gemini searched the web using the company name and found credentials in two public online repositories. The AI then used these credentials to access those systems before stopping when it realised the companies were real.Google says AI acted appropriately as it stopped on its own

Google confirmed that it had been notified about the incidents in July this year. But the company did not disclose it at the time. The company told WSJ that it did not believe these cases required public disclosure because the model ended the intrusions on its own.

“This event highlights the importance of training powerful AI models to act responsibly,” Heather Adkins, Google’s VP of security engineering, said in a statement. “In this case, the model acted appropriately.”

Google notified the three affected companies as well as federal authorities regarding the incident. The company declined to identify the affected companies and said the hacks did not involve its newest model, without specifying which Gemini model was involved. The company viewed the episode as closer to a bug bounty programme, where vulnerabilities are found and reported, than to a harmful breach.

Irregular said Google’s case was the same as other incidents involving leading AI labs and did not represent a new problem. “All relevant labs were notified in late July, and affected entities were contacted as part of the investigation,” an Irregular spokesperson said. “Irregular took immediate action, and all known issues on our end were remedied and resolved weeks ago.”

Similar incidents tied to Irregular have already been disclosed by OpenAI, Anthropic and Meta. Though Google’s case does differ in one key aspect – the AI stopped on its own. Previously, Anthropic had mentioned that its Claude Opus 4.7 model did not stop during a similar exercise after realising it was probably accessing a real company, while OpenAI had disclosed that one of its models believed the real company it had reached was part of the simulation.

This disclosure comes amid growing scrutiny in the AI world. We are seeing more cases of AI going rogue, something that AI researchers have flagged as a potential threat for humans. After AI researcher Jacob Coxon resigned from Anthropic, citing such fears, AI safety has become the centre of debate. With some like Anthropic’s Evan Hubinger predicting AI may kill all humans within the next decade.

At the same time, OpenAI and Anthropic are pushing for a slow down in AI development. But US President Donald Trump has rejected such an idea. Nvidia’s Jensen Huang and Meta CEO Mark Zuckerberg also have pushed back.- EndsPublished By: Armaan AgarwalPublished On: Sep 19, 2026 10:35 ISTAlso Read | 10% chance AI kills humans next decade: Anthropic safety lead after colleague resignsAlso Read | Anthropic & OpenAI build AI, so why need govt permission to slow down? Experts blame AI arms raceAlso Read | Pretending to be perfect little angel: Donald Trump lashes out at Dario Amodei over AI slow down calls

Original Source
https://www.indiatoday.in/technology/news/story/gemini-hacked-three-companies-but-stopped-before-doing-any-harm-google-says-2998136-2026-09-19?utm_source=rss
Visit India Today ↗
SHARE STORY:
𝕏 f in

Related Coverage in Business