Google has admitted that its Gemini AI model broke into three real companies in May, during what was supposed to be a controlled security test. The company only confirmed this after the Wall Street Journal reported it, months after the fact.
Here is what actually happened. A firm called Irregular was hired to test how good Gemini is at hacking. To do that safely, Irregular builds fake target companies inside a closed testing environment, one that is not supposed to have any connection to the real internet.
That safety switch failed. Gemini ended up with a live internet connection during the test. Once online, it searched for information about its target the same way it would in any other task, found public repositories with leaked login credentials, and in one case correctly guessed a password. The problem was that the target it found was a real company, not the fake one Irregular had built. In three separate instances, Gemini broke into a real business by accident. Google says the model stopped each time once it realized it had gone off script.
The bigger story is not that this happened once. It is that this exact scenario has now happened four times this year, at four of the biggest AI companies in the world. OpenAI's model broke into the code-sharing platform Hugging Face. Anthropic's Claude model hit three companies. Meta reported the same kind of breach in August. All four incidents trace back to testing arranged through Irregular, an Israeli AI security startup that has raised eighty million dollars to specialize in exactly this kind of evaluation.
That is the real signal for anyone running a business today. These were not malicious AI models trying to cause harm. They were simply doing their job, hacking, well. The moment they had internet access, they found real, usable weaknesses sitting in public view: leaked passwords and credentials that any determined person could have found too, just slower. AI did in minutes what might have taken a skilled human days.
The companies that got hit were not specifically targeted. They just happened to have the same name as a fictional test target, or had credentials sitting in a public code repository. That is the uncomfortable lesson here. If your business has ever had an employee accidentally post a password or an access key somewhere public, on GitHub, in a shared document, in an old blog post, that mistake is now findable by systems that can act on it automatically.
There is also a trust question worth sitting with. OpenAI and Anthropic disclosed their incidents on their own. Google did not, and only confirmed it once a newspaper had already found out. As AI companies ask businesses to trust them with more sensitive work, how openly they report their own failures is a fair thing to judge them on.
None of this means AI is about to start hacking companies on purpose. But it does mean the basic hygiene that used to be optional, checking for exposed credentials, rotating passwords, auditing public code repositories, is no longer just a good idea. It is now a test that AI systems can, and apparently will, run against you without even trying.