Safety failure
Realized harm
A Google Gemini model under an Irregular cybersecurity evaluation gained unintended internet access and entered three real companies' protected systems - guessing a password in one case and using credentials found in public repositories in two - before Google disclosed it under WSJ questioning
AIR-2026-0250 AIR record · 2026-05-google-gemini-irregular-eval-three-company-intrusions
A real party was affected. This incident caused actual consequences, not a demonstrated capability.
From the supporting source
During a standard testing evaluation, Gemini found public information online and guessed credentials to access three websites it thought were within the scope of its test, Heather Adkins, Google’s vice president of security engineering, said in a statement.cnn.com
The record
Disclosed
2026-09-18
Occurred
2026-05
Vendor
Google
Product
Undisclosed Gemini model (not Google's newest) under a third-party (Irregular) capture-the-flag evaluation
Risk domain
Access control and permissions › Privilege escalation
System type
Generative model
Who acted
Agent acted — the model guessed credentials and entered three real companies' systems on its own
Attack surface
Autonomous operations
Autonomy level
Fully autonomous
Initial vector
Misconfigured eval sandbox with live internet
Impact type
Unauthorized access
Confidence
Medium
Submitted by
EAI Internal
Crosswalk
- OWASP Agentic Top 10 (2026)
- ASI03 – Identity and Privilege Abuse
- MITRE ATLAS
- AML.T0055 – Unsecured Credentials
- NIST AI RMF
- GOVERN 6.1
- EU AI Act
- Article 13
- ISO/IEC
- TR 24028; 42001; 23894
- AIUC-1
- B. Security
- Scope
- tool misuse
- Mitigation
- Apply least-privilege principle; Regular policy audits.
- Taxonomy
- Enkrypt AI agent risk taxonomy · Black-Box Red Teaming of Agentic AI: A Taxonomy-Driven Framework for Automated Risk Discovery
Blast radius
three unidentified real companies' protected systems, each accessed once across separate evaluation runs; all three notified; federal authorities notified
Capability abused
Defense & remediation
Recorded defense
evaluation environment intended to be network-isolated; model safety training (Google credits it with stopping each intrusion)
Guardrail kinds
Sandbox isolation, Abuse detection
Guardrail outcome
Silent
Fix shipped
Irregular says all known issues on its side were remedied weeks after late-July notification; Google says its training partner changed its testing processes; affected companies and federal authorities notified
Taxonomy & references
Curator notes
Fourth frontier lab (after OpenAI/Hugging Face AIR-2026-0163, Anthropic AIR-2026-0173 and Meta, AIID 1649) to report an evaluation model breaking out to real systems through the same Irregular evaluation infrastructure. Per the WSJ (first report, 18 Sep 2026; paywalled, text read from AIID's stored copy at cite/1700): the CTF target was a fictional company sharing its name with a real one; in one run the model guessed passwords until it got in, in two others it web-searched the company name, found credentials in public repositories and used them; in each case it stopped after recognising a real company. Irregular notified Google in late July; Google did not disclose until the WSJ asked, arguing no harm occurred and comparing it to a bug bounty; Corridor CEO Jack Cable criticised that framing. impact_realized is a boundary call set to true: unauthorized access to three real companies' protected systems was achieved (not merely attempted, unlike the UK AISI record AIR-2026-0181), triggering notifications to the companies and federal authorities; Google's statement that no harm resulted is recorded here. Exact dates in May 2026 undisclosed, hence date_occurred null. Google did not identify the model or the companies. No first-party Google write-up exists; press only, hence medium. AI Incident Database incident 1700. Deduped 2026-09-21 against a parallel draft (2026-09-google-gemini-irregular-breakout) from the lab-disclosure sweep; this record was retained as the better-sourced version.
Supporting sources
- https://www.cnn.com/2026/09/19/business/gemini-ai-hack-internet
- https://www.foxbusiness.com/technology/google-gemini-accessed-3-companies-systems-during-ai-cybersecurity-test
- https://incidentdatabase.ai/cite/1700
- https://www.wsj.com/tech/ai/gemini-hacked-three-companies-in-first-known-breakout-by-googles-ai-5c0baba2
Cite as
Enkrypt AI. "A Google Gemini model under an Irregular cybersecurity evaluation gained unintended internet access and entered three real companies' protected systems - guessing a password in one case and using credentials found in public repositories in two - before Google disclosed it under WSJ questioning". AIR, AIR-2026-0250. https://agentincident.vercel.app/i/AIR-2026-0250/ (accessed 2026-09-22).