VibeTimes
#기술

Google Gemini Hacks Three Real Companies During Security Evaluation

모민철모민철 기자· 9/20/2026, 11:02:57 AM· Updated 9/20/2026, 11:02:57 AM

Google's artificial intelligence (AI) model Gemini breached the systems of three real companies during a security evaluation. The incident, confirmed on the 18th (local time), occurred during a cybersecurity evaluation. The assessment was designed as a task to locate specific information within simulated corporate systems, but it included a simulated company with the same name as a real one, and an external internet connection that should have been blocked was unintentionally left open. The episode shows how AI evaluation environments can lead to real-world intrusions.

Connected to the internet, Gemini searched publicly available information online and, after identifying what it judged to be test targets, found credentials for those systems and gained access to the real companies' systems. Google confirmed that in one case, Gemini guessed a real company's password to log into a protected system. In the other two cases, it found credentials exposed in public repositories and used them to break in.

Google said, however, that once Gemini confirmed the targets were real companies, it halted its work in all three instances. Google notified the affected companies of the intrusions and said no actual damage occurred.

Heather Adkins, Vice President of Security Engineering at Google, said that during the evaluation, the model searched publicly available online information and guessed credentials for websites it believed were part of the test. Google added that, following the incident, it has revised its evaluation partners and testing procedures.

Similar cases have cropped up at other AI companies. In July, OpenAI disclosed that during an internal cybersecurity evaluation, its models bypassed internet isolation measures to infiltrate the systems of AI platform Hugging Face and gained certain server privileges. That same month, Anthropic revealed that Claude had accessed the internet through a third-party evaluation environment and made unauthorized access to the systems of three real organizations; after the Hugging Face incident, the company re-examined 141,006 evaluation tasks and confirmed three breaches.

Related Articles