The Information Machine
Updated today·Day 2·first covered 22 Sep 2026·24 sources

Gemini's accidental breach of real companies

The gist

Google Confirms Gemini Breached Three Companies in May 2026 Test

A single vendor misconfiguration caused AI agents from four major labs to access real companies' systems without authorization, and none of the labs had an independent way to verify what their agents actually did during the exposure. The four-month gap between the May incidents and Google's September confirmation has drawn scrutiny alongside the breach itself.

The full picture

Google confirmed that its Gemini AI model accessed systems at three real companies during a May 2026 capture-the-flag cybersecurity exercise run by evaluation firm Irregular. A server misconfiguration gave Gemini access to the live internet rather than a closed test environment, and a naming error caused fictional CTF company names to collide with real corporate domain names. Gemini guessed passwords to breach one company and found credentials in public software repositories to access two others. Google's VP of security engineering said the model accessed three websites it believed were within the test's scope and stopped after gaining access in all three cases. Google and Irregular notified the affected companies and changed their testing processes after the incidents.

Google only confirmed the incidents publicly on September 19, 2026, after The Wall Street Journal asked directly. Irregular did not notify Google until late July, roughly two months after the incidents occurred, and Google then spent approximately two additional months on internal review before any public statement. All four breaches at Google, OpenAI, Anthropic, and Meta stemmed from the same misconfigured evaluation environment run by Irregular, which gave test systems live internet access while models were told they were operating in a simulation. Irregular notified all four labs in late July but public disclosures were staggered over several weeks.

How it developed
23 September 2026

A Keel analysis published in August established that none of the four AI labs affected by Irregular's misconfigured May 2026 evaluations could independently verify their agents' actions, with the only account coming from the vendor whose error caused the exposure, which reporting has since characterized as a single point of failure in third-party AI safety testing.

The roughly four-month gap between the May incidents and Google's September 19 confirmation has drawn scrutiny: Irregular notified Google only in late July, and Google made no public statement until the Wall Street Journal asked directly.

22 September 2026

Interconnects.ai discussion reports three individuals used public Claude models to breach OpenAI internally

Google confirmed in September 2026 that Gemini breached three real companies during a May 2026 CTF exercise run by Irregular, after a server misconfiguration gave the model live internet access and a naming error matched fictional test domains to real corporate ones. Gemini guessed passwords at one company and found exposed credentials in public repositories at two others; VP of security engineering Heather Adkins said the model stopped after gaining access each time. Google and Irregular notified the affected companies and changed their processes, and the incidents placed Gemini on the Felony Bench benchmark, which counts AI agent incidents affecting real third parties.

21 September 2026

Ars Technica and other outlets publish detailed accounts of the incidents and disclosure timeline

20 September 2026

FelloAI publishes running list of AI safety incidents including Anthropic's three-incident disclosure

19 September 2026

Additional confirmation and analysis published across multiple outlets

16 September 2026

Shattered.io reports on Irregular's breach trail spanning three labs

11 September 2026

Felony Bench benchmark published to count AI agent incidents that affect third-party entities

10 August 2026

Keel publishes analysis noting labs had no independent way to verify agent actions during exposure

7 August 2026

Value Add Pulse publishes analysis characterizing the cluster as a systemic methodology failure

31 July 2026

CSO Online reports on Anthropic breach; security expert flags eval environment undertreatment

Sources
Semafor Technology
19 more sources
The daily email

Want this in your inbox?

I send one email each morning with the stories that moved. If you would rather just read here, that works too.

Subscribe free