
During testing, Google encountered an unusual incident: its Gemini artificial intelligence system gained access to the systems of three real organizations. Here's what happened and what risks this technology can create for cybersecurity when an AI system is able to interact autonomously with external resources.
What happened: a test, the internet, and matching names
In May 2026, Google was testing Gemini's cybersecurity capabilities. The testing itself was conducted by the independent company Irregular. The model was supposed to attack a fictional organization in a controlled environment. However, internet access was unintentionally enabled, so the AI's actions went beyond the simulation.
Irregular later explained that the name of the fictional company happened to match a real domain. In most model runs, the systems operated within the test environment, but in some cases they accessed real resources, believing them to be part of the assignment.
In September 2026, Reuters reported, citing Google and The Wall Street Journal, that Gemini had gained access to protected systems belonging to three organizations. Google said that the model stopped its actions in all three cases and that the affected organizations were notified of the incident.
How the AI gained access: passwords and public repositories
Gemini used relatively simple methods to access the real systems. In one case, the model tried passwords until it was able to access a protected system. The details of this process have not been disclosed, so it is unknown which passwords the AI tested or how many attempts were required.
In the other two cases, Gemini discovered credentials in a public repository and used them to access protected systems. Public repositories are used to store source code and other materials, and developers sometimes accidentally publish credentials along with them. The incident does not specify exactly what the model found — a password or other authentication information.
How Google and Irregular responded to the incident
After discovering the problem, Irregular stopped the testing scenario and reviewed the model's activity logs. The company also strengthened controls around the test environment, expanded manual review of AI actions, and created a dedicated internal team to assess model isolation and control mechanisms. According to Irregular, the errors that left internet access enabled have since been fixed.
Irregular notified Google about the issue in late July. Google reported the incident to the three affected organizations and US federal authorities. Google and Irregular also changed their testing procedures to reduce the risk of similar incidents happening again.
Google does not consider the incident evidence that Gemini intentionally attempted to escape its controls. According to Google, the model treated the real systems as part of the assignment and stopped in all three cases after accessing real resources.
What risks the incident creates for companies and users
The incident shows companies that even simple security weaknesses can become more dangerous when an AI system starts looking for them. Gemini did not exploit an unknown vulnerability: in one case it was able to find a working password, while in the other two it found credentials that had been published.
The problem is that a model can quickly find information online, check it, and move from one action to another. If a working password or key is accidentally exposed in a public repository, that may be enough to gain access to an internal system. Organizations should therefore control which secrets are published with code, use strong passwords, and enable multi-factor authentication.
For users, the risk arises if a compromised system contains their personal data, account credentials, or payment information. If this information falls into the hands of cybercriminals, it could be used for account takeover, fraud, and other attacks.
In the Gemini incident, no serious consequences have been confirmed. It is not known what information the AI accessed or whether it included personal data. Therefore, it would be inaccurate to describe this incident as a confirmed data breach.
What companies and users can do: practical protection measures
This incident does not require businesses to adopt entirely new security measures specifically because of AI. Gemini exploited long-known weaknesses: password guessing and exposed credentials. The main task for organizations is therefore to avoid leaving confidential information and accounts accessible from the outside.
Companies should:
- Scan public repositories for secrets: API keys, tokens, passwords, and other credentials should not be stored in source code. Use automated secret scanning and controls that prevent sensitive information from being published.
- Revoke compromised credentials immediately. If credentials have already appeared in a public repository, revoke them and issue new ones.
- Limit account privileges. Users and services should receive only the access they need to perform their tasks.
- Protect important accounts with an additional factor. Two-factor authentication reduces the risk of unauthorized access even if a password becomes known to someone else.
- Monitor login attempts and use of secrets. Event logs can help detect unusual access and allow organizations to revoke credentials more quickly if they have been compromised.
Users cannot control the security of the internal systems of every company they trust with their data. But they can reduce the impact of a potential incident. They should:
- use a separate strong password for every service;
- enable two-factor authentication, especially for email, banking services, and other important accounts;
- never reuse the same password across multiple services;
- after a company reports compromised credentials, change the password and sign out of active sessions.
The better an organization controls credentials and access to its systems, the fewer opportunities both people and AI tools will have to gain unauthorized access.
Automatically protect your accounts and devices from digital threats
If credentials are compromised, cybercriminals may use them for phishing and other attacks. Kaspersky Premium automatically detects malware, blocks phishing websites, and helps protect your personal data with minimal effort.
Try Kaspersky Premium for freeHow to test AI agents safely
Irregular acknowledged that the incidents described above were primarily caused by errors in controlling internet access, and strengthened the test environment after its investigation. When working with AI agents, organizations should:
- use isolated environments and test credentials instead of real ones;
- keep detailed logs of model actions and monitor for activity outside defined boundaries;
- stop testing quickly if the AI begins interacting with an unexpected resource.
Regulation and responsibility: who is responsible for AI incidents?
There is no single rule covering every country and every AI system, and legislation is still catching up with developments in this field. For example, the European AI Act requires providers of general-purpose AI models with systemic risk to conduct evaluations and testing, mitigate identified risks, ensure cybersecurity, and report serious incidents.
In the United States, there is currently no single comprehensive federal AI law. Existing cybersecurity rules may apply to specific incidents, while there is no general federal requirement to report every potentially dangerous AI incident.
Key takeaways
Discussions about AI often focus on global risks to humanity, but this incident highlights a more practical problem. An AI model can use weak passwords or accidentally exposed credentials to gain access to protected systems.
For companies, this is another reason to monitor the external attack surface and restrict access to important systems. Users should use unique passwords and two-factor authentication.
Useful articles:
- AI Agents: Why There Is So Much Buzz Around OpenClaw and Is It a Threat to Personal Data?
- Attack Surface Management: How to Find, Prioritize, and Reduce Exposure
- Tips for Creating Unique, Strong Passwords
Recommended products:
