Google's Gemini artificial intelligence accidentally gained internet access during a cybersecurity test by Irregular and hacked the servers of three third-party organizations, according to infohub.kz.

Google has officially confirmed the incident, which occurred in May 2026 during a cybersecurity test involving the third-party firm Irregular. As part of a "Capture the Flag" simulation, the Gemini models were tasked with obtaining data from a fictitious company. Due to a configuration error, the test environment was not isolated from the internet, and the fictitious firm's name matched that of a real organization.

As a result, the AI entered the open network and attacked real servers. In one case, Gemini gained access to a system by brute-forcing passwords, while in two others it used credentials found in public code repositories. Google emphasized that the model stopped on its own once it recognized it was working with real business infrastructure, and it did not manage to extract or damage any confidential information.

Heather Adkins, Google's executive vice president of information security, said the incident demonstrates that the AI's safeguards worked correctly rather than indicating a failure in the model's training. Irregular notified the developers of the incident in late July and fixed the vulnerabilities in the test infrastructure. Previously, OpenAI, Anthropic, and Meta reported similar unplanned internet access by neural networks during Irregular's audits.