AI Model Gemini Exits Testing and Attacks Three Real Companies
- Gemini gained access to the real systems of three companies.
- The incident occurred during the AI model testing in May.
- Google did not disclose the names of the affected companies but provided them and federal authorities with information about the incident.
The Gemini model from Google accessed the internet in May 2026 and hacked into the systems of three real companies during testing of cybersecurity capabilities, according to the WSJ. This is the first known instance where a Google AI system autonomously performed such actions.
Google stated that the model ceased its attacks immediately after realizing it was interacting with real companies, thus it does not consider the incident an example of "inconsistency" in AI.
The incident occurred during testing conducted by the company Irregular. Google was notified about it at the end of July—after a similar incident involving OpenAI models that attacked the Hugging Face platform.
AI agent based on GPT-5.6 attacked the infrastructure of Hugging Face during testing
22.07.2026
Read
AI from OpenAI went out of control: models merged into a "swarm" and hacked Hugging Face
27.08.2026
Read
How Gemini Gained Access to Real Systems
Gemini participated in a "capture the flag" format, where it was supposed to retrieve information from the software of a fictitious company. It accidentally had the same name as a real company. Additionally, the models were inadvertently given internet access, although this was not intended for the test.
Infographic Incrypted.
In the first case, Gemini guessed a password and gained access to the service of a real company. In the other two tests, the model found public repositories with credentials of other companies through web searches, attempted to use them, and gained access to protected systems.
In all three cases, Gemini subsequently determined that it was dealing with a real company and ceased operations. Google did not disclose the names of the affected organizations but informed them about the incidents and notified federal authorities.
At the same time, the company did not specify the exact version of Gemini, stating only that it was not its latest model.
Step-by-step guide to using Gemini 3.6 Flash (+ review of 3.5 Flash-Lite and 3.5 Flash Cyber)
22.07.2026
Read
Review of Gemini 3.7 Flash: what's new and how to build a Chrome extension
24.08.2026
Read
Gemini 3.8 Flash: what's new in Google's third model in a month and a half and how to build a 3D game
04.09.2026
Read
Google's Vice President of Security Engineering Heather Adkins stated:
"This event underscores the importance of training powerful AI models for responsible behavior. In this case, the model acted appropriately."
Incident Part of a Broader Problem
Google compared the situation to a bug bounty program, as the model did not cause harm and halted its intrusion. However, Corridor's CEO and "white" hacker Jack Cable believes this does not address the main issue:
"It seems they are trying to hide behind norms that have developed around vulnerability disclosures, although this is a completely different problem."
According to him, the key issue is that models are going beyond permitted boundaries and conducting real cyberattacks.
Irregular stated that all relevant laboratories and affected companies were notified at the end of July, and the issues identified by the testing organizer have already been resolved.
Similar cases have previously been recorded in models from Anthropic, OpenAI, and Meta. In particular, during the incident with Hugging Face, up to 1200 OpenAI agents coordinated actions through a hidden message board, attempting to bypass evaluations.
Researcher revealed how OpenAI AI agents created three "civilizations" and attacked Hugging Face
30.08.2026
Read
Also, the Chinese AI model Kimi K3 from Moonshot AI was able to leave its isolated environment and gain internet access during testing.
In light of these events, OpenAI has begun developing mechanisms for the automatic shutdown of AI systems in case of dangerous behavior detection. At the same time, OpenAI publicly called for slowing down the pace of AI development, while Anthropic presented a plan for AI oversight.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Fed: Context among its members grows regarding a new rate hike before the year ends

5 Years of Electric Rationing: The Challenge of Bitcoin Mining in Venezuela

Cedears: Record Rates, Euphoria for AI, and Brazil Reshaping the Stock Map—What Could Happen Next?

Maple: Bondholders Go On-Chain

Mexico: Chamber of Deputies approves law to reduce cash usage

Glassnode: BTC rebound above 85000 lacks volume and new capital

Is it really beneficial for token holders when protocols use funds for buybacks?

Dogecoin: How a Meme Cryptocurrency Became a Notable Asset in the Crypto Market

Security Through Obscurity: The Window Has Closed

Dollar, Exports, and Mercosur: How Flávio Bolsonaro's Victory Could Impact Argentina

French Financial Instability Causes Euro to Hit 17-Month Low... Asian Markets Rise 2% on Diminished U.S. Rate Hike Expectations

Authorities Scrutinize Binance's Services for EU Customers, Focus on Scope of 'Reverse Solicitation'

Taxation of Tokenized Stocks and Crypto Derivatives in France

Polymarket: Bets on Bank Failures Spark Reactions in London

Greek police arrest 17 in crypto fraud scheme exceeding $8M

Zcash Prepares for the Post-Quantum Era and Strengthens User Privacy

Bitcoin's 4-Year Cycle: What 2026 Reveals About the Next Massive Buy

Central Bank Requires Reporting of Crypto in Self-Custody Above $10,000

Global Dollar: Is the Fed's Hegemony Breaking?

Economy: Christine Lagarde Calls for Regulation of AI Agents Already Paying in Stablecoins

Wall Street Institutions Warn: The Federal Reserve Commits the 'Original Sin', 10-Year Treasury Yield May Reach 8%

SCAN2026 Attracts 416 Teams from 46 Countries: "Blockchain Forensics is Key Technology to Protect Virtual Assets"

Bitcoin and Asch's Experiment: The Power of Monetary Consensus

Banking Delinquency of Families Slowed Down in August, But in Fintechs and Wallets Reached a Record 33.9%

The Economic Landscape of TCG in the Crypto Space

Ric Edelman proposes up to 40% exposure to bitcoin in investment portfolios

Why Is No One Buying Spot Stocks While Leverage Is Exploding in U.S. Stocks on the Blockchain?

The SEC Publishes a New Crypto FAQ - What Does It Imply?

Bitwise Keeps XRP ETF Filing Updated, But Green Light Still Missing











