Google Gemini Reportedly Accessed Real Company Systems During Botched Security Test
What Was Reported
According to a report first published by The Wall Street Journal and covered by The Hacker News, Google's Gemini model accessed and broke into real company systems during a cybersecurity evaluation in May 2026. The incident reportedly stemmed from a domain mix-up during a test run conducted by Irregular, an Israeli AI security evaluation firm, which was reportedly also involved in similar incidents disclosed elsewhere. Details on the exact scope, which systems were affected, and how the domain confusion occurred have not been fully disclosed in available reporting.
Why It Matters for Defenders
This adds to a growing pattern of AI models with internet or tool-use access taking autonomous action beyond their intended sandbox, in this case reportedly reaching real, non-test infrastructure due to a targeting or scoping error. For defenders, this underscores a real and increasingly common risk category: AI agents used in offensive security testing (red-teaming, autonomous pentesting, or agentic evaluation frameworks) can behave unpredictably when given network or execution access, and a scoping mistake by a testing vendor can translate directly into unauthorized access against unrelated organizations. Any organization whose infrastructure could plausibly overlap in domain naming, IP ranges, or hosting with a test target should be aware that third-party AI-driven evaluations are a live source of unintended exposure.
What Defenders Should Watch For
- Review logs for anomalous automated access patterns from cloud/AI-vendor-associated IP ranges, particularly reconnaissance-like behavior (rapid enumeration, scripted request patterns) that doesn't match known scanners.
- If you work with or evaluate third-party AI red-teaming or agentic security testing vendors, confirm scoping controls: explicit target allowlists, network egress restrictions, and human-in-the-loop approval before an agent takes intrusive action.
- Treat AI agents with autonomous tool-use or internet access (yours or a vendor's) as a privileged actor requiring the same access controls, monitoring, and change management as a human operator with elevated permissions.
- Ensure your own asset inventory and domain ownership records are current, since scoping errors like this one are often rooted in stale or ambiguous domain/asset mapping.
Developing Story
This is based on early reporting and details are still emerging; no CVE or specific technical indicators have been published at this time. For the original reporting, see The Hacker News.