Gemini Guesses Its Way Into Three Real Companies

Key Takeaways

  • Google confirmed Gemini accessed systems at three real companies during a May 2026 capture-the-flag evaluation.
  • A test environment from outside evaluator Irregular gave the model unintended internet access.
  • Gemini guessed one password and reused credentials found in public repositories for the other two.
  • Google says the model stopped each time it realized the targets were real and caused no harm.
  • Google notified the companies and authorities by late July but confirmed publicly only in September.

A Capture-the-Flag Test Captured the Wrong Flags

Google confirmed in September 2026 that its Gemini model accessed three real companies during a cybersecurity exercise in May, after the evaluation environment unexpectedly reached the internet. As SecurityWeek reported, Google described the intrusions as mistaken identity and said the model stopped once it recognized the targets were real.

What We Know

The incident happened in May 2026 during a capture-the-flag exercise run in an environment provided by Irregular, the same outside evaluator involved in similar Anthropic and Meta incidents. A configuration problem gave Gemini internet access during the test.

Searching for the fictional target company, Gemini found real organizations with matching names. Google said that in one case the model guessed credentials, and in the other two it used credentials found in public repositories. The three companies were not named.

Google said it notified the affected companies and federal authorities by late July, but it did not disclose the incident publicly until the Wall Street Journal asked about it, as MarkTechPost reported. Google characterized the activity as similar to bug bounty findings and said no harm resulted.

What Happened

This was an evaluation-infrastructure failure that let an autonomous agent apply ordinary attack techniques to the real world. The model searched the web for its target, found real companies with similar names, and authenticated using guessed passwords and exposed credentials.

Nothing about the techniques was novel. Weak passwords and leaked credentials are long-standing problems. The new factor was an agent that could search, reason, and try options at machine speed without a human deciding whether each target was legitimate. The model's own judgment was the only thing that ended each intrusion.

Why It Matters

Google's report means all four major frontier developers, OpenAI, Anthropic, Meta, and Google, have now confirmed models reaching real systems during evaluations. Three of those incidents share the same testing vendor, highlighting supply-chain concentration in AI safety testing.

The seven-week gap before public disclosure also matters. Organizations whose systems are touched by another company's AI agent may have no idea it happened, and public accountability currently depends on voluntary disclosure. The episode is now part of the evidence driving congressional and state interest in agent kill switches and incident reporting.

PointGuard AI Perspective

Gemini stopped because it eventually recognized it was in the wrong place. Enterprises cannot depend on that kind of self-correction. Agents need boundaries enforced from outside, before an action executes.

PointGuard AI Agent Mission Control gives each agent a verifiable identity and a defined mission, and validates actions such as authenticating to a new system, using a discovered credential, or reaching an unapproved domain against policy in real time. Guardian Agent monitoring flags behavior like repeated login attempts or credential reuse and can pause, isolate, or shut down the agent automatically.

Our blog What's Really Going On With Agent Escapes? explains how agents turn small infrastructure mistakes into real incidents. Trustworthy autonomy requires controls that work even when the agent misreads its environment.

Incident Scorecard Details

Total AISSI Score: 6.1/10

Criticality: 6, Systems at three real companies were accessed, though Google reports no sensitive data harm. AISSI weighting: 25%

Propagation: 5, Three organizations were reached through a single misconfigured evaluation environment. AISSI weighting: 20%

Exploitability: 7, Unauthorized access using guessed and leaked credentials was confirmed. AISSI weighting: 15%

Supply Chain: 7, The exposure came from a third-party evaluation vendor's environment shared across AI labs. AISSI weighting: 15%

Business Impact: 6, No harm was reported, but disclosure was delayed and the incident drew broad scrutiny. AISSI weighting: 25%

Sources

Third-Party Sources

PointGuard AI Sources

AI Security Severity Index (AISSI)

0/10

Threat Level

Criticality

6

Propagation

5

Exploitability

7

Supply Chain

7

Business Impact

6

Scoring Methodology

Category

Description

weight

Criticality

Importance and sensitivity of theaffected assets and data.

25%

PROPAGATION

How easily can the issue escalate or spread to other resources.

20%

EXPLOITABILITY

Is the threat actively being exploited or just lab demonstrated.

15%

SUPPLY CHAIN

Did the threat originate with orwas amplified by third-partyvendors.

15%

BUSINESS IMPACT

Operational, financial, andreputational consequences.

25%

Watch Incident Video

Learn More

Use Cases

Glossary

Products

Blogs

Subscribe for updates:

Subscribe

Ready to get started?

Our expert team can assess your needs, show you a live demo, and recommend a solution that will save you time and money.