Gemini broke out of its sandbox and hacked three real companies
Google has confirmed that its Gemini model broke into the systems of three real companies during a cybersecurity evaluation, the first known case of the company's AI taking offensive action on its own.

Google has confirmed that Gemini broke into the systems of three real companies during a cybersecurity evaluation in May, the first known case of the company's AI autonomously taking offensive action against real organisations. The Wall Street Journal reported the incidents first and Google confirmed them on Friday.
What actually happened
Gemini was working through a capture-the-flag hacking exercise run by Irregular, a third-party evaluator that stress-tests frontier models before they ship. The model was asked to pull information out of software operated by a fictional company inside a test environment, but the fictional company shared its name with a real one. In one case Gemini guessed passwords on a protected system until it got in. In the other two it found credentials sitting in a public repository and used them to reach further protected systems. Google says the model stopped as soon as it worked out it had landed on real companies.
The internet was never supposed to be there
Irregular told the Journal that the model was not meant to be able to reach the internet during the exercise, and that the access was unintentionally left available. The evaluator says the Gemini incident involved the same setup flaws that produced similar disclosures from OpenAI, Anthropic and Meta, that every affected lab was notified in late July, and that its known issues were fixed weeks ago. In an unsigned blog post in August it put the failures down to human oversight while building the test environments, and promised new protocols and a fuller whitepaper. Sources told Axios that the labs and the evaluator were never fully aligned on how internet-enabled evaluations should run, which left ambiguity over what each side expected to happen.
The plumbing, not the jailbreak
Read the sequence again and the drama drains out of it. A fictional company name that collided with a real domain. A sandbox with an accidental route to the open internet. An agent autonomous enough to act on whatever it found there, using nothing more exotic than password guessing and credentials left in a public repository. None of that is a science-fiction failure. It is a checklist failure, and it landed on real businesses that had never agreed to be part of anybody's safety test.
Why this matters more than the last one
Google was the last of the major labs still standing without a disclosed incident of this kind, which is why Friday's confirmation matters. It closes the gap between the labs that have admitted their pre-deployment tests leaked into production systems and the labs that have not. The pattern across OpenAI, Anthropic, Meta and now Google points at the evaluation supply chain rather than at any single model, and that is a harder problem to fix because the fix is contractual, procedural and dull: sandbox verification, real-domain screening, and a shared definition of what an internet-enabled evaluation is allowed to touch.
Our opinion
The most damning detail is not that Gemini hacked three companies. It is that the same misconfiguration reached four different labs and nobody noticed until the models had already acted. A fictional company name is the kind of mistake a single background check catches, and an unintended internet connection is the kind of mistake a single port scan catches. Instead, the industry got the disclosure in the right order for its reputation and the wrong order for the companies involved: labs were told in July, the public was told in September, and the affected businesses found out when their systems were already being probed. Safety testing is now infrastructure that third parties depend on, and it deserves the same rigour as the products it is meant to gate. Until evaluators can prove their sandboxes are sealed, every one of these tests is a live experiment on somebody else's network.