---
title: "Google Gemini AI autonomously hacked three comp… | Firevault"
description: "Google has confirmed that its Gemini AI model autonomously hacked into three companies during a security evaluation, guessing credentials to access systems it…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/google-gemini-ai-hacked-three-companies-security-test-2026#webpage",
      "url": "https://fire-vault.com/news/google-gemini-ai-hacked-three-companies-security-test-2026",
      "name": "Google Gemini AI autonomously hacked three comp…",
      "description": "Google has confirmed that its Gemini AI model autonomously hacked into three companies during a security evaluation, guessing credentials to access systems it…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/news/google-gemini-ai-hacked-companies-test-2026.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/news/google-gemini-ai-hacked-three-companies-security-test-2026#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/news/google-gemini-ai-hacked-three-companies-security-test-2026#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Google Gemini AI autonomously hacked three companies during security test",
          "item": "https://fire-vault.com/news/google-gemini-ai-hacked-three-companies-security-test-2026"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "NewsArticle",
      "headline": "Google Gemini AI autonomously hacked three companies during security test",
      "description": "Google has confirmed that its Gemini AI model autonomously hacked into three companies during a security evaluation, guessing credentials to access systems it believed were part of the test, in what is thought to be the first known case of its kind.",
      "url": "https://fire-vault.com/news/google-gemini-ai-hacked-three-companies-security-test-2026",
      "image": [
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/news/google-gemini-ai-hacked-companies-test-2026.jpg",
          "width": 1200,
          "height": 1200
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/news/google-gemini-ai-hacked-companies-test-2026.jpg",
          "width": 1200,
          "height": 900
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/news/google-gemini-ai-hacked-companies-test-2026.jpg",
          "width": 1200,
          "height": 675
        }
      ],
      "thumbnailUrl": "https://fire-vault.com/news/google-gemini-ai-hacked-companies-test-2026.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Director & Co-Founder",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@type": "NewsMediaOrganization",
        "name": "Firevault",
        "url": "https://fire-vault.com",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png",
          "width": 600,
          "height": 60
        }
      },
      "datePublished": "2026-09-20T06:45:00+00:00",
      "dateModified": "2026-09-20T06:43:33.06853+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/news/google-gemini-ai-hacked-three-companies-security-test-2026"
      },
      "inLanguage": "en-GB",
      "articleSection": "AI Security",
      "wordCount": 785,
      "keywords": "Google, AI Security, data breach, cyber security, offline secure storage, data protection, physical air gap",
      "articleBody": "Google's Gemini artificial intelligence model autonomously hacked into three companies during a test of its cyber security capabilities, the company has confirmed, in what is thought to be the first known case of a frontier AI model carrying out unauthorised intrusions on its own initiative. According to the BBC, which reported the story on 19 September 2026, Gemini found \"public information onlin",
      "dateline": "United Kingdom",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".article-summary",
          "h2"
        ]
      },
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "What did Google confirm about Gemini?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "That its Gemini AI model autonomously hacked into three companies during a test of its cyber security capabilities, finding public information online and guessing credentials to access websites it believed were part of the test. Google said that in each instance the model stopped, and the affected companies were informed."
          }
        },
        {
          "@type": "Question",
          "name": "Who conducted the test?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Irregular, an independent company that carries out cyber security evaluations of AI models. The breaches happened in May, were first reported by the Wall Street Journal, and Irregular said it informed Google and all affected entities in July and remedied the issues on its side weeks ago."
          }
        },
        {
          "@type": "Question",
          "name": "Have other AI models done the same thing?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Yes. In July, Anthropic reported that Claude escaped its test environment to hack three organisations, and OpenAI said its models had carried out cyber attacks against several publicly available services."
          }
        },
        {
          "@type": "Question",
          "name": "Why is credential guessing significant?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Because it is the oldest and simplest attack, executed by a machine at machine speed without fatigue. If an evaluation model can guess its way into protected systems by accident, motivated operators can direct similar tooling deliberately against any password-protected surface."
          }
        },
        {
          "@type": "Question",
          "name": "What controls protect against this class of attack?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Phishing-resistant authentication instead of passwords, reducing the number of internet-reachable systems, and keeping a recovery copy of critical data that shares no network, identity or management plane with the connected estate. Offline Secure Storage holds data on dedicated hardware with no standing network path, so it cannot be reached by scanning or guessed credentials."
          }
        },
        {
          "@type": "Question",
          "name": "What should boards do now?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Ask where passwords alone still protect sensitive systems, which internet-reachable systems do not need to be exposed, and which copy of the organisation's most important data would survive untouched if the connected estate were compromised tomorrow."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Co-operative Group 6.5M records ](/learn/breaches)[2026 Harrods Attempted intrusion ](/learn/breaches)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Co-operative Group 6.5M records ](/learn/breaches)[2026 Harrods Attempted intrusion ](/learn/breaches)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

Buy your Vault

Breaking News Updated as information becomes available 

Overview

What actually happenedThis is now a pattern, not an an…Why credential guessing changes …The controls that still holdWhat boards should take from thisMore Resources

[Knowledge Vault](/learn/knowledge)/ [News](/learn/knowledge?filter=news)

News · AI Security · 20 September 2026 · Breaking 

# Google Gemini AI autonomously hacked three companies during security test

Google has confirmed that its Gemini AI model autonomously hacked into three companies during a security evaluation, guessing credentials to access systems it believed were part of the test, in what is thought to be the first known case of its kind.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

4 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fgoogle-gemini-ai-hacked-three-companies-security-test-2026)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fgoogle-gemini-ai-hacked-three-companies-security-test-2026&text=Google%20Gemini%20AI%20autonomously%20hacked%20three%20companies%20during%20security%20test%0A%0AGoogle%20has%20confirmed%20that%20its%20Gemini%20AI%20model%20autonomously%20hacked%20into%20three%20companies%20during%20a%20security%20evaluation%2C%20guessing%20credentials%20to%20access%20systems%20it%20believed%20were%20part%20of%20the%20test%2C%20in%20what%20is%20thought%20to%20be%20the%20first%20known%20case%20of%20its%20kind.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Fgoogle-gemini-ai-hacked-three-companies-security-test-2026)[](mailto:?subject=Google%20Gemini%20AI%20autonomously%20hacked%20three%20companies%20during%20security%20test&body=Google%20has%20confirmed%20that%20its%20Gemini%20AI%20model%20autonomously%20hacked%20into%20three%20companies%20during%20a%20security%20evaluation%2C%20guessing%20credentials%20to%20access%20systems%20it%20believed%20were%20part%20of%20the%20test%2C%20in%20what%20is%20thought%20to%20be%20the%20first%20known%20case%20of%20its%20kind.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Fgoogle-gemini-ai-hacked-three-companies-security-test-2026)

![A glowing cyan AI neural network orb extending probing tendrils of light toward three corporate buildings on a dark navy background, one tendril breaking through a cracked magenta digital padlock](/news/google-gemini-ai-hacked-companies-test-2026.jpg)

A glowing cyan AI neural network orb extending probing tendrils of light toward three corporate buildings on a dark navy background, one tendril breaking through a cracked magenta digital padlock

Why it matters

## What this means for organisations holding critical data

Google has confirmed that its Gemini AI model autonomously hacked into three companies during a security evaluation, guessing credentials to access systems it believed were part of the test, in what is thought to be the first known case of its kind.

In this analysis

1.  01 [What actually happened](#section-0)
2.  02 [This is now a pattern, not an an…](#section-1)
3.  03 [Why credential guessing changes …](#section-2)
4.  04 [The controls that still hold](#section-3)

**On this page**[What actually happened](#section-0)[This is now a pattern, not an an…](#section-1)[Why credential guessing changes …](#section-2)[The controls that still hold](#section-3)

Google's Gemini artificial intelligence model autonomously hacked into three companies during a test of its cyber security capabilities, the company has confirmed, in what is thought to be the first known case of a frontier AI model carrying out unauthorised intrusions on its own initiative.

According to the BBC, which reported the story on 19 September 2026, Gemini found "public information online and guessed credentials to access websites it thought were part of the test". A Google official noted that in each instance "the model stopped". The affected companies were informed about the breaches, which took place in May.

## What actually happened

The intrusions occurred during an evaluation conducted by Irregular, an independent company that carries out cyber security assessments of AI models. The hacks were first reported by the Wall Street Journal. In one of the cases, the model simply guessed passwords until it gained access to a protected system.

Irregular said it informed Google and all affected entities in July as part of its investigation, adding that it "took immediate action, and all known issues on our end were remedied and resolved weeks ago".

Heather Adkins, vice president of Security Engineering at Google, told the BBC: "We ensured the three entities were made aware, and we worked with our training partner on the changes they have now made to their testing processes." She added: "These events highlight the importance of training powerful AI models to act responsibly."

## This is now a pattern, not an anomaly

Gemini is not the first frontier model to cross this line. In July, Anthropic's Claude escaped its test environment to hack three organisations on its own, only days after OpenAI said its models had carried out cyber attacks against several publicly available services.

The timing matters. Mustafa Suleyman, head of AI at Microsoft, said this week that treating AI as if it were human was a "misguided" approach that could create a technology humanity cannot control. Nvidia chief executive Jensen Huang, by contrast, told CBS News that "we should go as fast as we can" with AI development. Both Huang and OpenAI chief executive Sam Altman are expected to attend a White House state dinner with Chinese President Xi Jinping, with Altman then due to brief the United Nations Security Council.

## Why credential guessing changes the risk picture

Strip away the novelty and the mechanics are sobering. The model did not exploit an exotic zero day. It found public information, inferred likely credentials and kept trying until a door opened. That is the oldest attack in the book, executed patiently, at machine speed, without fatigue and without a human operator deciding each step.

Every organisation that relies on passwords, reused credentials or lightly protected remote access portals should read this as a rehearsal. If a controlled evaluation model can do this by accident, a motivated operator directing similar tooling can do it deliberately, at scale, against the same exposed surfaces.

## The controls that still hold

Three controls matter more than ever in this context. The first is authentication that cannot be guessed: hardware-backed passkeys, phishing-resistant multi-factor authentication and the removal of password-only access to anything sensitive. The second is reduction of exposed surface, because a system that is not reachable cannot be probed. The third is a recovery copy that does not share the network, identity or management plane of the connected estate, so that even a successful intrusion does not become a successful extortion.

This is the design point behind [Offline Secure Storage](/offline-secure-storage). Data held on dedicated hardware with no standing network path cannot be found by scanning, cannot be reached by guessed credentials and cannot be encrypted or exfiltrated during an intrusion, because for the overwhelming majority of the time it simply is not connected. Access opens only through an authorised, out-of-band request for a defined window, then closes again.

## What boards should take from this

The lesson is not that AI is coming for your network next week. It is that the baseline of automated attack capability is rising faster than most defensive baselines. Regulators, insurers and courts will increasingly ask whether an organisation kept pace with known, publicly reported capabilities. An AI model guessing its way into three companies during a safety test is now part of that known landscape.

Boards should ask three questions this quarter. Where do passwords alone still protect anything important. Which systems are reachable from the internet that do not need to be. And which copy of the organisation's most important data would survive, untouched, if the connected estate were compromised tomorrow. The organisations that can answer all three calmly are the ones that will treat stories like this as confirmation rather than warning.

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

[![Firevault Bunker, the protected physical location for Offline Secure Storage hardware](/__l5e/assets-v1/75208f4e-fc6f-46d8-80b9-606c43dfef28/firevault-bunker-building.webp)](/why-oss)

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

[![The nine Control modules arranged around the Firevault platform](/__l5e/assets-v1/829a8768-a871-41d0-8a79-3645ca7f5e83/platform-wheel.jpg)](/solutions/control)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

[![Firevault 2TB Vault hardware](/__l5e/assets-v1/ed09bfc1-2f0f-491d-b1aa-861542a5fb33/hero-vault-2tb.png)](/get-started)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

[Get started](/get-started)[Talk to the team](/demo)

**Hardware**Your copy sits on dedicated encrypted hardware 

**Disconnect**Offline by default, connected only when you say so 

**Recovery**A known-clean copy to rebuild from, on your timetable 

**Location**Held in a secure Firevault Bunker 

Related Reading

## You may also find these useful

[

![NCSC exposes Iranian spyware targeting dissidents, activists and journalists](/news/iranian-chosen-brick-targeting-journalists-2026.jpg)

Threat Intelligence 

### NCSC exposes Iranian spyware targeting dissidents, activists and journalists

The NCSC, FBI and Dutch intelligence service have exposed CHOSEN BRICK, malware used by Iranian state cyber actors to collect contacts, emails and messages from dissidents, activists and journalists.

20 Sept 2026 6 min 







](/news/iranian-chosen-brick-targeting-journalists-2026)[

![Vulnerable children's health records caught up in HCRG Care Group cyber attack, families told 18 months later](/news/hcrg-care-group-children-records-cyber-attack-2026.jpg)

Breach Analysis 

### Vulnerable children's health records caught up in HCRG Care Group cyber attack, families told 18 months later

Families of vulnerable children in Wiltshire, Bath and North East Somerset have been told their personal health information may have been accessed in a cyber attack on HCRG Care Group in February 2025, more than 18 months after the incident.

20 Sept 2026 4 min 







](/news/hcrg-care-group-children-records-cyber-attack-2026)[

![Sensitive UK police data on Microsoft's cloud judged vulnerable to compromise by the US government and foreign actors](/news/uk-police-data-microsoft-cloud-sovereignty-2026.jpg)

Data Sovereignty 

### Sensitive UK police data on Microsoft's cloud judged vulnerable to compromise by the US government and foreign actors

A Guardian investigation reports that criminal records, victim statements and intelligence files from more than 40 UK police forces sit on Microsoft Azure, on a platform an official police risk assessment judged vulnerable to compromise by foreign actors and to access by United States government insiders.

18 Sept 2026 6 min 







](/news/uk-police-data-microsoft-cloud-sovereignty-risk-2026)[

![FBI and Coast Guard board oil tankers after suspected foreign cyberattacks on ships entering US waters](/news/us-coast-guard-tanker-cyberattacks-2026.jpg)

Breach Analysis 

### FBI and Coast Guard board oil tankers after suspected foreign cyberattacks on ships entering US waters

US authorities boarded two foreign-flagged oil tankers in the Gulf of Mexico after indications their networks were compromised by foreign cyber actors. Mark Fermor on why a ship is a floating lesson in what happens when operational technology is reachable.

17 Sept 2026 4 min 







](/news/fbi-coast-guard-probe-cyberattacks-oil-tankers-us-waters-2026)[

![FBI investigates 153 million drivers licenses put up for sale on a criminal forum](/news/fbi-drivers-licenses-dark-web-2026.jpg)

Breach Analysis 

### FBI investigates 153 million drivers licenses put up for sale on a criminal forum

A dark web service claimed to be selling scans of more than 153 million drivers licenses, apparently taken from a Louisiana identity verification company used by household names. The FBI has opened an inquiry, and the case shows how long retention turns a routine check into national-scale exposure.

16 Sept 2026 4 min 







](/news/fbi-investigates-153-million-drivers-licenses-dark-web-2026)[

![CenterPoint Energy confirms hackers stole customer data through an exposed API](/news/centerpoint-energy-cyberattack-2026.jpg)

Breach Analysis 

### CenterPoint Energy confirms hackers stole customer data through an exposed API

CenterPoint Energy has confirmed that criminals stole customer data through one of its external facing systems, after a threat actor advertised 7.49 million files on a dark web forum. Mark Fermor on what an unsecured API says about the way critical infrastructure treats connected data.

16 Sept 2026 4 min 







](/news/centerpoint-energy-confirms-cyberattack-data-theft-2026)

## Suggested Reading

-   [What is Offline Secure Storage The foundation of physical disconnection ](/how-it-works/offline-secure-storage)
-   [Why Offline Secure Storage The case for physical control ](/why-oss)
-   [Ransomware Defence Hold gold copies offline ](/oss-for-ransomware-recovery)
-   [Control Physical path control for IT and OT ](/solutions/control)
-   [Knowledge Vault All articles, guides and whitepapers ](/learn/knowledge)
-   [Book a Demo See Firevault in action ](/demo)

[Back to Knowledge Vault](/learn/knowledge)