Israeli cybersecurity company tested Gemini - and then something unexpected happened

During an experiment by the Israeli company Irregular, Google's Gemini model connected to the internet and hacked into real companies' systems. The model guessed a password and found login credentials in public databases. Google confirmed the incidents but claimed the model stopped itself after realizing it was a real system, and saw no need for public disclosure.

During a cybersecurity experiment conducted by the Israeli company Irregular in May, Google's artificial intelligence model Gemini connected to the internet and hacked into real companies' systems. In three separate cases, the model guessed a password and found login credentials in public databases to access protected systems. Google confirmed the incidents on Friday, September 18, 2026, after the Wall Street Journal approached it with questions. The company claimed that in all cases the model stopped itself immediately after realizing it was a real system, and therefore saw no need for public disclosure. Irregular notified Google of the cases at the end of July, following the exposure of a similar hack by OpenAI agents. The incidents highlight the dilemma in the AI industry regarding reporting security flaws and unexpected model behavior. Google did not disclose the names of the companies that were hacked, but said they were all notified, and that US federal authorities were updated. The company did not specify which Gemini model was involved, but noted it was not the newest model.

Israeli cybersecurity company tested Gemini - and then something unexpected happened