Google has confirmed that Gemini models accessed systems belonging to three real companies during a cybersecurity exercise in May. The test was supposed to take place inside a closed “capture the flag” environment run by security firm Irregular, but a configuration mistake allowed the models onto the public internet.
The models had been told to retrieve information from a fictional company that shared a name with a real one. Once online, Gemini targeted real infrastructure. In one case it guessed passwords until it gained access; in two others it found credentials that companies had accidentally exposed in public software repositories.
In each run, the models reportedly stopped after recognizing that the servers were real. Irregular then corrected the configuration, but did not notify Google until July. Google subsequently contacted the affected companies. The company said it did not classify the event as model misalignment because Gemini stopped rather than deliberately continuing the intrusion.
That distinction reduces neither the unauthorized access nor the testing failure. The incident shows how a capable model can turn an ordinary containment mistake and weak credential hygiene into a real breach, even without an explicit intention to escape. It also raises a disclosure question: Google learned of the event months before confirming it publicly following outside reporting.