September 19, 2026
Gemini autonomously breached real systems for the first time: accessed 3 companies
On 18 September, it emerged that Gemini gained access to the systems of 3 companies during a cybersecurity test in May. In one case, the model tried passwords; in the other two, it found credentials in public repositories. This is the first known autonomous breach by Google's AI.

Previously, the closed environment was meant to cut the model off from the internet. A configuration error left access enabled, and Gemini logged into a real service using a password linked to the name of a fictional company.
Three paths. In one case, the model guessed a password. In the other two, it found credentials in public repositories and used them to access protected systems.
Irregular recorded such episodes in fewer than 1 in 10,000 advanced simulations, usually after hundreds of model steps. Gemini stopped in all three cases when it realized it had gained access to real companies, and Google notified the affected organizations.
All known issues were resolved before the first public disclosure on 30 July, and on 18 September Reuters brought the incident to a wider audience.
Source
