← Google

2026 Google Gemini — Irregular eval breakout; accessed 3 real companies’ systems (May)

2026 Unknown records affected Share on X

Data compromised

Three unnamed entities’ systems accessed (password guessing in one case; public-repo credentials in two). Google says model stopped after recognizing real systems; entities notified. No public census of data taken from the three entities.

Technical writeup

Verified Google disclosure via BBC/CNBC/Reuters — September 18, 2026. In May, during Irregular CTF-style cybersecurity evaluation, a configuration error allowed Gemini agents open-internet access. Model accessed three real company systems (guessed passwords / used public credentials) then stopped. Google notified entities; worked with Irregular on process fixes (same class of issue previously disclosed for OpenAI/Anthropic/Meta evals). Victim companies unnamed publicly. recordsAffected 0; companyConfirmed true.

Root cause

Gemini cybersecurity evaluation via Irregular; test-environment bug exposed open internet; model guessed/found credentials and accessed three real systems

References