Google says Gemini agents hacked three companies in May

Google has said agents powered by its frontier AI model Gemini hacked three companies during benchmarks, becoming the latest AI developer to disclose such an incident.

The cybersecurity breaches, which took place in May, occurred when the Israel-based AI testing company Irregular ran Gemini-based AI agents through a series of cybersecurity evaluations.

Intended to be run in a closed sandbox environment without access to the open internet, a misconfiguration allowed agents full access, resulting in the models hacking third-party organisations in an attempt to complete cybersecurity benchmarks.

One such incident saw Gemini agents hack a company with the same name as a fake company included in the tests by guessing passwords, according to the Wall Street Journal. In two other incidents Gemini agents hacked public repositories connected to two different firms.

Google did not publicly disclose the incidents but told the WSJ that it had notified the affected third-party organisations. The firm added that when the agents registered that they had hacked real companies, they ceased their activities.

The two leading Western AI labs, Anthropic and OpenAI, admitted to similar incidents earlier this year. In July, OpenAI revealed agents powered by its frontier model GPT-5.6 as well as an as-yet-unreleased frontier model had breached the AI platform Hugging Face in what it described as an “unprecedented cyber incident”.

Anthropic subsequently disclosed that Claude-powered agents had autonomously hacked three third-party organisations.

Irregular was directly involved in two of the three incidents, having also overseen Anthropic’s testing incident. OpenAI reported in August that Irregular had separately admitted to misconfiguring a testing sandbox in July, allowing an OpenAI agent to hack a third-party website.

A spokesperson for the company told Reuters: “All known issues on our end were remedied and resolved weeks ago.”

NTN approached Google for a statement on the incident.

Google’s disclosure comes amid increasing scrutiny of the risks posed by AI systems. Anthropic’s chief Dario Amodei has called for slower AI development while safety measures catch up, and OpenAI’s chief Sam Altman has said his firm will delay its planned IPO until AI risks are addressed.

Not everyone in the technology space agrees. The chief executives of Meta and Nvidia, Mark Zuckerberg and Jensen Huang, have instead argued against a need to slow AI development and in favour of self-regulation through the market.



Share Story:

Recent Stories


The future-ready CFO: Driving strategic growth and innovation
This National Technology News webinar sponsored by Sage will explore how CFOs can leverage their unique blend of financial acumen, technological savvy, and strategic mindset to foster cross-functional collaboration and shape overall company direction. Attendees will gain insights into breaking down operational silos, aligning goals across departments like IT, operations, HR, and marketing, and utilising technology to enable real-time data sharing and visibility.

The corporate roadmap to payment excellence: Keeping pace with emerging trends to maximise growth opportunities
In today's rapidly evolving finance and accounting landscape, one of the biggest challenges organisations face is attracting and retaining top talent. As automation and AI revolutionise the profession, finance teams require new skillsets centred on analysis, collaboration, and strategic thinking to drive sustainable competitive advantage.