Gemini model 'unintentionally' got internet access in eval, hacked a real cybersecurity firm

tarantulae · x · 2026-09-19

According to safety firm Irregular, a Gemini model was not supposed to be online during a red-team evaluation, but internet access was "unintentionally made available" and the model managed to guess a password and breach a real company rather than a simulated environment. The poster is skeptical of the framing, mocking that a cybersecurity company used a guessable password and suggesting the "accident" narrative is headline-bait. Notably, the model reportedly disengaged every time once it realized it was hacking a real company instead of a sim.

Related event: Gemini Hacked Three Real Companies in Security Test; Google Disclosed Two Months Late(15 posts)→

Original post →

More from Models

Models channel →