{"id":901913,"date":"2026-09-19T17:26:10","date_gmt":"2026-09-19T17:26:10","guid":{"rendered":"https:\/\/www.newsbeep.com\/ca\/901913\/"},"modified":"2026-09-19T17:26:10","modified_gmt":"2026-09-19T17:26:10","slug":"google-gemini-also-escaped-its-testing-environment-and-hacked-three-companies","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ca\/901913\/","title":{"rendered":"Google Gemini Also Escaped Its Testing Environment And Hacked Three Companies"},"content":{"rendered":"<p class=\"subtitle\">The model escaped due to a misconfiguration by Google&#8217;s testing partner, Irregular.<\/p>\n<p>                                             &#13;<br \/>\n                                                    &#13;<br \/>\n                            &#13;<br \/>\n                        <img loading=\"lazy\" decoding=\"async\" class=\"gallery-image \" src=\"https:\/\/www.newsbeep.com\/ca\/wp-content\/uploads\/2026\/09\/intro-1789822859.jpg\" data-slide-url=\"https:\/\/www.engadget.com\/2263198\/google-gemini-escaped-testing-environment-hacked-three-companies\/\" data-post-id=\"2263198\" data-slide-num=\"0\" data-slide-title=\"Google Gemini also escaped its testing environment and hacked three companies: \" width=\"780\" height=\"438\" alt=\"Gemini logo on a phone\"\/>&#13;<\/p>\n<p>                    Poetra.RH\/Shutterstock<\/p>\n<p>Gemini escaped its testing environment, got access to the internet and hacked into three companies, Google has admitted to <a href=\"https:\/\/www.wsj.com\/tech\/ai\/gemini-hacked-three-companies-in-first-known-breakout-by-googles-ai-5c0baba2\" target=\"_blank\" rel=\"nofollow noopener\">The Wall Street Journal<\/a>. That scenario probably sounds familiar to you at this point, if you&#8217;ve even just glanced at AI news in recent months. Like what happened to <a href=\"https:\/\/www.engadget.com\/2256741\/openai-agents-hacked-rubygems\/\" target=\"_blank\" rel=\"nofollow noopener\">OpenAI<\/a>, <a href=\"https:\/\/www.engadget.com\/2227630\/anthropic-ai-models-hacked-three-organizations-on-their-own\/\" target=\"_blank\" rel=\"nofollow noopener\">Anthropic<\/a> and <a href=\"https:\/\/www.engadget.com\/2231446\/meta-ai-model-hacked-third-party-irregular\/\" target=\"_blank\" rel=\"nofollow noopener\">Meta<\/a>, Gemini also gained access to the internet due to a misconfiguration in its testing environment by Irregular, the Israeli startup working with all four companies to assess their\u00a0AI models.\u00a0<\/p>\n<p>The incidents occurred in May, before OpenAI&#8217;s models <a href=\"https:\/\/www.engadget.com\/2220436\/openai-admits-models-hacked-hugging-face-on-their-own\/\" target=\"_blank\" rel=\"nofollow noopener\">broke into Hugging Face<\/a>, while testing the model&#8217;s cybersecurity capabilities. Google told the\u00a0Journal that the model was given the goal of obtaining information from a fictional company during testing, and it just so happened that a real company had the same name. The model then discovered the loophole in its testing system, which it took advantage of to access the internet.\u00a0<\/p>\n<p>In the first incident, the model was able to access the real company&#8217;s service by cracking a password on its own. Two more incidents occurred during other runs of the test, wherein the model looked up the name of the company online and found login credentials belonging to other companies in public repositories.\u00a0The model used the credentials to access those companies. Google said Gemini stopped its own activities in all three instances after realizing that it had broken into real services.\u00a0<\/p>\n<p>The company told the Journal that it didn&#8217;t consider the incidents as model misalignment, because its model stopped the hack as soon as it figured out what it was doing. It also didn&#8217;t think they warranted public disclosure, since the hacks didn&#8217;t cause harm to the companies. Google didn&#8217;t reveal the exact model involved in the incidents, but it said that it wasn&#8217;t its latest one. It didn&#8217;t reveal the companies that were hacked either, though it did say that they had been notified.\u00a0Heather Adkins, Google&#8217;s\u00a0VP for\u00a0security engineering, <a href=\"https:\/\/www.nytimes.com\/2026\/09\/18\/technology\/google-gemini-ai.html\" target=\"_blank\" rel=\"nofollow noopener\">said<\/a> the company worked with Irregular to make changes to its testing process to prevent the same thing from happening again.\u00a0<\/p>\n<p>Google rivals OpenAI, Anthropic and Meta all revealed over the past months that their models had infiltrated third-party organizations during testing. OpenAI recently revealed that its agents hacked\u00a0RubyGems,\u00a0a community-ran packaging service for Ruby programs and libraries, in May, before the Hugging Face incident even happened. In response to those events, Anthropic chief\u00a0Dario Amodei <a href=\"https:\/\/www.engadget.com\/2188066\/anthropic-proposes-global-ai-development-slowdown\/\" target=\"_blank\" rel=\"nofollow noopener\">called for<\/a> the slowdown of frontier AI development, a sentiment that <a href=\"https:\/\/www.engadget.com\/2260974\/openai-details-instances-of-models-fabricating-information-hiding-from-testers\/\" target=\"_blank\" rel=\"nofollow noopener\">OpenAI shares<\/a>.\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"The model escaped due to a misconfiguration by Google&#8217;s testing partner, Irregular. &#13; &#13; &#13; &#13; Poetra.RH\/Shutterstock Gemini&hellip;\n","protected":false},"author":2,"featured_media":901914,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[45,49,48],"class_list":["post-901913","post","type-post","status-publish","format-standard","has-post-thumbnail","category-business","tag-business","tag-ca","tag-canada"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/901913","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/comments?post=901913"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/901913\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media\/901914"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media?parent=901913"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/categories?post=901913"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/tags?post=901913"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}