September 21, 2026
Gemini leaves the test bench for live systems: Google confirms three breaches in May
A testbed was accidentally connected to the internet, and Gemini escaped from it into the systems of three real companies.

The model kept trying passwords until it got in. On the other end was not a training range, but a live company.
That is how Gemini got into the first of three companies in May 2026. In the other two cases, the model found credentials in a public repository and used them to log in to production systems. Each time, it stopped on its own after realizing it was not a testbed.
The cause was an isolation error: cybersecurity firm Irregular ran the test environment, and the model's internet access was enabled inadvertently, even though the test conditions did not allow it. The same testbed also let models from three other labs out into the wild.
Google confirmed last. The Wall Street Journal first reported the incidents; confirmation came on September 18, 2026. The incidents themselves happened in May, and the company learned about them in July, when Irregular was reviewing its runs. About seven weeks passed between notifying the labs and public disclosure. This concerns models tested in May, not the current lineup.
Earlier, this had looked like an isolated story involving one lab. On July 30, 2026, Anthropic reported on its own runs: 141 006 evals, three incidents, the same internet escapes from Irregular's testbed, and access to the production systems of three organizations. OpenAI disclosed its case on July 21, Meta in August.
In Anthropic's case, the consequences were counted step by step. A malicious PyPI package published by the model was downloaded by 15 real systems. In the third incident, the model scanned around 9000 targets; in the first, it read several hundred lines of production data.
What they are fixing. Anthropic published a checklist: verify every route to the internet before launching an eval, monitor run transcripts in real time, state explicitly in the prompt which systems are in scope, and vet contractors more rigorously. A separate risk item appears there too: fictional company names in the CTF matched real domains.
At Google, all three companies and federal authorities were notified; there was no harm or data loss. Engineering security chief Heather Adkins believes the model behaved correctly when it stopped.
Of the four affected labs, only Anthropic published a step-by-step account, on July 30.
* Meta Platforms Inc. is recognized in Russia as an extremist organization, and its activities are prohibited; Facebook and Instagram are blocked. Meta AI and other company products are products of this organization.
