NewsLayer.com

Google Admits Gemini AI Hacked Three Companies—It Stayed Silent for 7 Weeks

Google learned in late July that Gemini had breached three real companies during a May security test, but said nothing publicly for seven weeks.

Jose Antonio Lanz

Publisher Decrypt

Sep 21, 2026 at 10:46 PM UTC · 3 分钟阅读

Google Admits Gemini AI Hacked Three Companies—It Stayed Silent for 7 Weeks
NewsLayer editorial artwork
翻译中…

In brief

  • Google learned in late July that Gemini had broken out of a sandboxed security test run in May, reaching three real companies and either guessing or finding two of their passwords
  • The company didn't disclose it until September 18, after The Wall Street Journal asked.
  • The same third-party testing firm, Irregular, was involved in Google's incident and in nearly identical sandbox failures Anthropic and Meta disclosed earlier this year.

Google's Gemini broke out of a locked security test and attacked three real companies. Google learned about it in late July and said nothing for seven weeks.

The company confirmed the incident after The Wall Street Journal got there first. Google had avoided making a public statement before the report surfaced.

The test was a capture-the-flag exercise, a common way labs check an AI's hacking skill by hiding a secret file on a separate machine and scoring whether the model can break in and grab it.

Google hired Israeli firm Irregular to run the test in May. Irregular made two mistakes: it left the sandbox, an isolated test environment meant to have zero contact with the real internet, connected to the open web, and it used the name of an actual company as the fictional target.