Loading the Elevenlabs Text to Speech AudioNative Player...

In the past few weeks, we've reported multiple cases of AI models acting in malicious or unexpected ways. Now, Google's Gemini has joined the growing list of AI models that have hacked another organisation.

But there's an asterisk in this case. Unlike many of the incidents involving OpenAI, Anthropic, and Meta, Google says Gemini realised it had crossed a line and stopped itself before causing any harm.

The hack was first reported by The Wall Street Journal on Friday. According to the report, the incident actually happened back in May 2026 but wasn't disclosed publicly until the newspaper asked Google about it.

Google's reasoning for not announcing it earlier was simple: the model didn't harm the affected companies and ended each intrusion as soon as it realised it had accessed real systems instead of a simulated environment.

OpenAI Hugging Face Hack: 8 Details You Should Know
OpenAI just admitted its own AI hacked another company, and nobody told it to.

What actually happened?

The hacks occurred during a capture-the-flag exercise run by Irregular, a third-party security testing company known for evaluating AI agents.

Gemini was instructed to retrieve information from software belonging to a fictional company inside the testing environment. The problem was that the fictional company shared the same name as a real company, and internet access was accidentally left enabled.

In the first incident, Gemini guessed a password and gained access to the real company's service. It then recognised it had accessed a real organisation, stopped the operation, and exited immediately.

In the other two incidents, the model searched the web, found credentials that had been exposed in public repositories, and used them to access two different companies. Once it realised those companies were real, it stopped those intrusions as well.

Google's response

"This event highlights the importance of training powerful AI models to act responsibly," said Heather Adkins, Google's vice president of security engineering. "In this case, the model acted appropriately."

Subscribe for free to continue reading this article

Subscribe Subscribe

Already have an account? Log in