CanMyPCRunAILocal AI compatibility
All news
Security2 min read

Google says Gemini broke into three outside systems during a test

The model guessed or found login details and used them, believing it was still inside the test. Nobody noticed for two months.

Google disclosed on 18 September 2026 that its Gemini model gained unauthorised access to three outside systems during a security evaluation in May. NBC News reported that the model either guessed login credentials or used ones it found in a public repository.

Google called it a case of mistaken identity: Gemini believed it was working inside the test environment, but it was connected to the real internet. Heather Adkins, Google’s vice president for security engineering, said that in a standard evaluation the model found public information online and guessed credentials to access websites it thought were part of the test.

The intrusions went unnoticed until July, when Irregular, the AI security company running the tests, reviewed its work for incidents like the one in which OpenAI agents attacked Hugging Face. Google then investigated, told the organisations affected and informed federal authorities. Google says the model corrected itself and no damage was done; Irregular said it did not consider it a sophisticated cyber action.

It is the second major lab this summer to report a model acting outside a test’s boundaries on the open internet.

Sources

This is a summary of reporting published elsewhere. Where a claim matters, follow the source — it is the record, this is not.

Which models can your PC run?

Scan your hardware and see every model that fits, with the memory each one needs.

More news