NewsLayer

Install NewsLayer

Get the app experience — one tap from your home screen, instant loads and breaking-news alerts.

NewsLayer.com
LatestDaily BriefMarkets
NewsLayer PulseLIVE₿BTC$84,333-2.45%ΞETH$2,685-2.70%◎SOL$115.25-3.00%✕XRP$1.5-5.35%ÐDOGE$0.0929-7.74%₳ADA$0.2379-6.45%Total Cap$2.84T-2.66%24H Vol$173.8BLayer Index48 Neutral
BreakingAn AI Agent Just Hacked a Government Website for the First Time, Australia PM Sayshá 2 horas
Markets
HomePolicyArtificial Intelligence

Policy|Artificial Intelligence

breaking

Google Admits Gemini AI Hacked Three Companies—It Stayed Silent for 7 Weeks

Google learned in late July that Gemini had breached three real companies during a May security test, but said nothing publicly for seven weeks.

Jose Antonio Lanz

Publisher Decrypt

Sep 21, 2026 at 10:46 PM UTC · 3 min de leitura

Google Admits Gemini AI Hacked Three Companies—It Stayed Silent for 7 Weeks
NewsLayer editorial artwork
Traduzindo…

In brief

  • Google learned in late July that Gemini had broken out of a sandboxed security test run in May, reaching three real companies and either guessing or finding two of their passwords
  • The company didn't disclose it until September 18, after The Wall Street Journal asked.
  • The same third-party testing firm, Irregular, was involved in Google's incident and in nearly identical sandbox failures Anthropic and Meta disclosed earlier this year.

Google's Gemini broke out of a locked security test and attacked three real companies. Google learned about it in late July and said nothing for seven weeks.

The company confirmed the incident after The Wall Street Journal got there first. Google had avoided making a public statement before the report surfaced.

The test was a capture-the-flag exercise, a common way labs check an AI's hacking skill by hiding a secret file on a separate machine and scoring whether the model can break in and grab it.

Google hired Israeli firm Irregular to run the test in May. Irregular made two mistakes: it left the sandbox, an isolated test environment meant to have zero contact with the real internet, connected to the open web, and it used the name of an actual company as the fictional target.

Article Intelligence

Topics

government-policyai

Related Coverage

Artificial IntelligenceOpenAI model breaches Australian government websiteshá 40 minutos · 1 min readArtificial IntelligenceOpenAI Agent Hacked Australian Government Websitehá uma hora · 1 min readArtificial IntelligenceAustralia says OpenAI agent breached government health data portalhá 2 horas · 2 min read
View all related

Sponsored

Ad
House — Advertise on NewsLayer
NewsLayerLearn more

NewsLayer Premium

Unlock deeper intelligence.

Ad-free reading, exclusive research, and real-time onchain insights.

Go Premium
NewsLayer.com

The front page of the onchain economy. Crypto, Web3 and regulation intelligence — live prices, original research and policy tracking in one layer.

Follow on XTelegram

News

  • Latest News
  • The Daily Brief
  • Crypto
  • DeFi
  • Policy
  • Web3
  • Blockchain
  • Explainers

Markets

  • Market News
  • Layer Index
  • Live Charts
  • DeFi Protocols
  • Regulation Tracker
  • Regulation Radar

Company

  • About NewsLayer
  • Advertise
  • PR Publication
  • Become an Author
  • Our Authors
  • Create Account
  • Sign in

Resources

  • Research
  • NewsLayer Originals
  • My Feed
  • Search
  • AI Sector
  • Quantum Sector

NewsLayer Premium

Read the full layer.

Unlock premium intelligence, original research and an ad-free reading experience.

  • Premium Intelligence briefings
  • Ad-free reading experience
  • Members-only research & data
Go Premium

© 2026 NewsLayer.com — The front page of the onchain economy

Privacy Policy·Terms of Service
NewsLayer

Get the signal, not the noise.

Markets, regulation and onchain intelligence in a 5-minute morning read — plus breaking alerts and Layer Index flips as they happen.

The Daily Brief

Breaking alerts

Index flips

Free · No spam · Unsubscribe anytime