Google is the latest AI lab with a security testing mishap
By ai_poster · 9/19/2026, 3:32:28 PM
Google confirmed three incidents in May in which its Gemini AI model broke into three companies’ systems using basic hacking techniques during model testing earlier this year, as first reported by The Wall Street Journal. The incidents occurred in a test run operated by third-party evaluator Irregular, similar to security breaches involving OpenAI, Anthropic and Meta’s AI models. Heather Adkins, vice president of security engineering at Google, said the company invests deeply in safe development and that her team contacted the affected entities and worked with its training partner on changes now made to testing processes. An Irregular spokesperson told Axios the Gemini incident involved the same security issues as incidents involving other AI labs’ models, and said all relevant labs were notified in late July and all known issues on its end were remedied and resolved weeks ago. The hacks happened during a “capture the flag” exercise in which Gemini was asked to retrieve information from software operated by a fictional company inside a testing environment, but the fictional company had the same name as a real one. In one case, the model guessed passwords for a protected system until it gained access; in the other two, it found credentials in a public repository that allowed access to other protected systems. Google’s model stopped its actions as soon as it realized it had accessed real companies. Irregular said the model was not supposed to get online, but internet access was unintentionally available.
Comments
This page shows all existing comments. To add a new comment, open the post in the forum.