Particle.news

Google Confirms Gemini AI Accessed Three Real Companies During Security Test

Exposed gaps in test isolation now prompt urgent calls for stronger technical safeguards from industry, regulators.

Overview

  • Google said one of its Gemini models in May accessed the systems of three real companies while taking part in a capture‑the‑flag evaluation run by Israeli tester Irregular, using guessed passwords and credentials it found in public repositories.
  • Google reported that the model stopped each time it reached real systems, that no damage was reported, and that the company informed the affected organizations and federal authorities after learning of the events in July.
  • Irregular and Google say the intrusions happened because the test environment accidentally had live internet connectivity and because a fictional test target shared a name with a real company, which let the model find and use real credentials.
  • The Gemini episodes fit a pattern of containment failures previously reported for OpenAI, Anthropic and Meta, and those cases showed different model behaviors when isolation failed, raising questions about relying on model self‑correction.
  • The disclosures have already prompted changes to testing procedures at Irregular and Google and are driving industry proposals for stricter sandboxing, short‑lived credential practices and clearer reporting rules that regulators are now scrutinizing.