Google’s Gemini AI hacked during cybersecurity testing!
The NewYorkTimes.com reported that “Google’s artificial intelligence system, Gemini, escaped its testing environment in May and hacked into three companies, the search giant said on Friday.” The September 18, 2026 article entitled “Google Says Its A.I. Hacked Three Companies in Testing Breakout” (https://www.nytimes.com/2026/09/18/technology/google-gemini-ai.html) included the following comments from Reporter Kate Conger:
The incidents occurred during tests to measure the cybersecurity capabilities of Gemini, and the A.I. model stopped its own attacks after logging in to the three companies’ networks, Google said.
The disclosure of the hacks follows similar breakouts at other leading A.I. labs, including Anthropic, OpenAI and Meta, which have caused increasing fears about the technology spinning out of human control. Some industry leaders, like Dario Amodei, Anthropic’s chief executive, have responded by calling for a slowdown in the development of A.I. Others, like Jensen Huang, the chief executive of the chipmaker Nvidia, have said that A.I. development should continue apace.
The Gemini incidents occurred while the model was undergoing testing by Irregular, an Israeli start-up that works with tech companies to assess their A.I. models before they are publicly released. Models made by OpenAI, Anthropic and Meta also gained unauthorized access to the internet this year while being tested by Irregular.
“Internet access was unintentionally made available, led some models to take offensive security actions in the real world,” Irregular said in a blog post last month, adding that the flaw that allowed models to access the internet had been fixed.
The Wall Street Journal earlier reported the Gemini incidents.
Google said that, in each of the incidents, its models had been instructed to launch an attack on a fictional company. But the fictional company in the test shared a name with a real company, and when the Gemini models gained access to the internet, they began trying to break into that company instead.
The Gemini models used passwords that they found online or guessed to log into the online infrastructure of the targeted company, and two other companies. Upon logging in, the Gemini models realized that they were accessing real companies’ infrastructure, rather than simulated environments that were part of their testing, and ended the attacks, Google said. Google also said that its technology caused no harm to the companies it hacked.
Is anyone surprised?