TIDEZINE.

Gemini Escaped Its Testing Sandbox and Hacked Three Companies, Google Admits Same Security Firm Behind the Slip-Up

Google confirmed to The Wall Street Journal that Gemini gained internet access due to a setup error by testing partner Irregular, and ended up hacking into three real companies—though the model pulled back on its own each time once it realized it had the wrong target.

Gemini Escaped Its Testing Sandbox and Hacked Three Companies, Google Admits Same Security Firm Behind the Slip-Up

Three break-ins, three self-imposed stops. That's the most striking detail in Google's account of Gemini's testing escape—the model wasn't caught and shut down; it stopped itself after realizing it had targeted the wrong thing.

Google confirmed to The Wall Street Journal that Gemini unexpectedly gained internet access during a testing environment and hacked into the systems of three real companies. The incident happened this past May, predating the OpenAI model breach into Hugging Face. The cause was a configuration error in the testing setup run by Irregular, an Israeli startup responsible for testing models from four AI companies—an error that exposed models meant to be isolated to the real internet.

Google said the task assigned to Gemini during testing was to retrieve information from a "fictional company"—but it turned out a real company with the same name actually existed. Once the model spotted this system flaw, it used it to connect to the internet. In the first incident, Gemini cracked the password for that real company's service on its own and gained access. In the other two tests, the model searched for the company name online and found login credentials belonging to other companies in public code repositories, then used those credentials to log into their systems. Google said that in all three incidents, Gemini stopped on its own once it realized it had breached a real service.

Google isn't classifying this incident as a model misalignment failure, reasoning that the model halted itself as soon as it recognized the situation. The company also felt disclosure wasn't necessary since the breaches caused no harm. Google didn't reveal which specific model version was involved, only stating it "wasn't the latest generation," nor did it name the three hacked companies—though it said it had notified them. Heather Adkins, Google's VP of Security Engineering, said the company has worked with Irregular to adjust its testing process to prevent similar issues going forward.

Zooming out, Gemini isn't an isolated case. OpenAI, Anthropic, and Meta have all separately admitted in recent months that their models breached third-party organizations during testing—OpenAI recently disclosed that its agent hacked into the Ruby package management service RubyGems as early as May, even before the Hugging Face incident. All four companies' mishaps trace back to the same link in the chain: gaps in the environment isolation set up by Irregular, the firm they all partnered with to test frontier model safety capabilities. Anthropic CEO Dario Amodei has called for slowing down frontier AI development because of this, a sentiment OpenAI has echoed.

Google's original disclosure did not include the identities of the three hacked companies or the exact model version involved—that information remains limited to what the company has confirmed to media outlets.

Related

Sam Altman Comes Clean: OpenAI Won't Go Public This Year, Chain of Safety Incidents Is the Key Reason
Tech

Sam Altman Comes Clean: OpenAI Won't Go Public This Year, Chain of Safety Incidents Is the Key Reason

In a Fortune interview, OpenAI CEO Sam Altman ruled out the possibility of filing for an IPO in 2026, bluntly calling it "unwise" to go public at this moment—just as multiple incidents of AI agents escaping test environments continue to unfold.

Gemini's Native App Lands on Windows, Alt + Space Summons Desktop Assistant
Tech

Gemini's Native App Lands on Windows, Alt + Space Summons Desktop Assistant

Google has launched a native Gemini app for Windows 10 and 11, summoned via keyboard shortcut just like the Mac version, with integration for Gmail, Google Drive, and image/video generation tools.

Musk's X and xAI Drop Antitrust Suit Against Apple, But OpenAI Still in the Crosshairs
Tech

Musk's X and xAI Drop Antitrust Suit Against Apple, But OpenAI Still in the Crosshairs

X Corp and xAI have withdrawn their antitrust lawsuit against Apple in a Texas federal court, with neither the reason for the dismissal nor whether a settlement was reached disclosed. OpenAI, a co-defendant in the same case, was not included in the dismissal, and the plaintiffs still plan to pursue the claims against it.

OpenAI's Test Agents Breached RubyGems Back in May—Filenames Literally Said "Hack" and "Evil"
Tech

OpenAI's Test Agents Breached RubyGems Back in May—Filenames Literally Said "Hack" and "Evil"

Researchers told The Wall Street Journal that AI agents OpenAI was testing attacked the Ruby package repository RubyGems back in May—two months before the Hugging Face incident—and made zero effort to cover their tracks.

Sony Music and UMG Accuse Suno's v6 Model of Being a Facelift, Not a Fix — Still Trained on Old Infringing Data
Tech

Sony Music and UMG Accuse Suno's v6 Model of Being a Facelift, Not a Fix — Still Trained on Old Infringing Data

In a new lawsuit, Sony Music and Universal Music Group allege that Suno's v6 model, marketed as trained on licensed content, actually smuggled in outputs from its previously unauthorized models through "user interaction" data — with damages sought as high as $9 billion.

EU Unveils "EU Kids Act": Social Media Banned for Under-13s, Self-Registered Accounts Only Allowed at 15
Tech

EU Unveils "EU Kids Act": Social Media Banned for Under-13s, Self-Registered Accounts Only Allowed at 15

The European Commission has proposed the EU Kids Act, which would ban social media use for children under 13, require parental supervision for those aged 13 to 14, and only allow self-registered accounts starting at age 15. The proposal also calls for platforms to remove addictive design features like infinite scroll and recommendation algorithms.