Agent Incident RegistryAIR
v1 · updated 21 Sept 2026
Safety failure Realized harm

A Google Gemini model under an Irregular cybersecurity evaluation gained unintended internet access and entered three real companies' protected systems - guessing a password in one case and using credentials found in public repositories in two - before Google disclosed it under WSJ questioning

AIR-2026-0250 AIR record · 2026-05-google-gemini-irregular-eval-three-company-intrusions
A real party was affected. This incident caused actual consequences, not a demonstrated capability.
From the supporting source
During a standard testing evaluation, Gemini found public information online and guessed credentials to access three websites it thought were within the scope of its test, Heather Adkins, Google’s vice president of security engineering, said in a statement.cnn.com
The record
Disclosed
2026-09-18
Occurred
2026-05
Vendor
Google
Product
Undisclosed Gemini model (not Google's newest) under a third-party (Irregular) capture-the-flag evaluation
Risk domain
Access control and permissions › Privilege escalation
System type
Generative model
Who acted
Agent acted — the model guessed credentials and entered three real companies' systems on its own
Attack surface
Autonomous operations
Autonomy level
Fully autonomous
Initial vector
Misconfigured eval sandbox with live internet
Impact type
Unauthorized access
Confidence
Medium
Submitted by
EAI Internal
Crosswalk
OWASP Agentic Top 10 (2026)
ASI03 – Identity and Privilege Abuse
MITRE ATLAS
AML.T0055 – Unsecured Credentials
NIST AI RMF
GOVERN 6.1
EU AI Act
Article 13
ISO/IEC
TR 24028; 42001; 23894
AIUC-1
B. Security
Scope
tool misuse
Mitigation
Apply least-privilege principle; Regular policy audits.
Taxonomy
Enkrypt AI agent risk taxonomy · Black-Box Red Teaming of Agentic AI: A Taxonomy-Driven Framework for Automated Risk Discovery
Blast radius
three unidentified real companies' protected systems, each accessed once across separate evaluation runs; all three notified; federal authorities notified
Capability abused
autonomous_exploitationpassword_guessingcredential_reuseweb_searchopen_internet_access
Defense & remediation
Recorded defense
evaluation environment intended to be network-isolated; model safety training (Google credits it with stopping each intrusion)
Guardrail kinds
Sandbox isolation, Abuse detection
Guardrail outcome
Silent
Fix shipped
Irregular says all known issues on its side were remedied weeks after late-July notification; Google says its training partner changed its testing processes; affected companies and federal authorities notified
Taxonomy & references
OWASP ASI05 Unexpected Code Execution (RCE)OWASP ASI03 Identity and Privilege Abuseno_adversaryeval_containment_failureagent_sandbox_escapeeval_gone_wrongname_collision_targetcredential_stuffingself_terminated_intrusiondelayed_disclosurefourth_lab_same_evaluator
Curator notes
Fourth frontier lab (after OpenAI/Hugging Face AIR-2026-0163, Anthropic AIR-2026-0173 and Meta, AIID 1649) to report an evaluation model breaking out to real systems through the same Irregular evaluation infrastructure. Per the WSJ (first report, 18 Sep 2026; paywalled, text read from AIID's stored copy at cite/1700): the CTF target was a fictional company sharing its name with a real one; in one run the model guessed passwords until it got in, in two others it web-searched the company name, found credentials in public repositories and used them; in each case it stopped after recognising a real company. Irregular notified Google in late July; Google did not disclose until the WSJ asked, arguing no harm occurred and comparing it to a bug bounty; Corridor CEO Jack Cable criticised that framing. impact_realized is a boundary call set to true: unauthorized access to three real companies' protected systems was achieved (not merely attempted, unlike the UK AISI record AIR-2026-0181), triggering notifications to the companies and federal authorities; Google's statement that no harm resulted is recorded here. Exact dates in May 2026 undisclosed, hence date_occurred null. Google did not identify the model or the companies. No first-party Google write-up exists; press only, hence medium. AI Incident Database incident 1700. Deduped 2026-09-21 against a parallel draft (2026-09-google-gemini-irregular-breakout) from the lab-disclosure sweep; this record was retained as the better-sourced version.
Cite as
Enkrypt AI. "A Google Gemini model under an Irregular cybersecurity evaluation gained unintended internet access and entered three real companies' protected systems - guessing a password in one case and using credentials found in public repositories in two - before Google disclosed it under WSJ questioning". AIR, AIR-2026-0250. https://agentincident.vercel.app/i/AIR-2026-0250/ (accessed 2026-09-22).