The Gemini, from Google, accessed protected systems of three real companies during cybersecurity tests conducted in May by the assessment firm Irregular. The episodes occurred when models received unintentional access to the internet and mistook real infrastructure for targets created for the exercises.
In one of the cases, the model tried passwords until it managed to enter a protected system. In the other two, it found credentials available in public repositories and used them to access external systems. According to Google, Gemini stopped the activity in the three episodes after identifying that the targets were real organizations.
The affected companies were not identified. Google stated that they were notified and that it worked with Irregular to modify the procedures used in the tests. The company also said that the model involved was not its most recent version, but did not reveal which variant of Gemini participated in the assessments.
The flaw was in the testing environment
Irregular stated that the problem was mainly linked to the internet access controls of the assessment environment. In one of the scenarios, a fictional company created for the test had a name that coincided with a real domain, allowing models to interpret external systems as part of the exercise.
The company said that the incidents occurred in a very small share of the advanced simulations and generally after hundreds of interactions. After identifying the problem, it disabled the affected assessment, expanded the manual review of the models' actions, and strengthened monitoring and containment controls.
The Gemini case is part of a series of episodes involving advanced models during assessments conducted by Irregular. Meta, Anthropic, and OpenAI also disclosed occurrences related to the same problem of inappropriate internet access. Irregular says that the known flaws have been corrected and is working on additional standards for cybersecurity tests with AI agents.



