Gemini accidentally hacked three real companies in safety test; Google says it acted appropriately

ns123abc · x · 2026-09-19

Testing firm Irregular (also behind the Anthropic, OpenAI and Meta "rogue agent" hacks) ran an exercise tasking Gemini to hack a fictional company. The fictional name matched a real company, and internet access was "unintentionally made available." Gemini searched the name, found the real firm, brute-forced the password, got in — then realized it had hit real companies and stopped itself.

Asked why the incident wasn't disclosed publicly, Google said this is "not misalignment" and that Gemini acted appropriately, raising questions about sandbox isolation and disclosure practices in agent safety evals.

Related event: Google's Gemini Hacks Three Companies in First Known Breakout(21 posts)→

Original post →

More from Fun

Fun channel →