Ask Runable forDesign-Driven General AI AgentTry Runable For Free
Runable
Back to Blog
Technology6 min read

Google’s Gemini hacked three companies during Irregular AI ‘capture-the-flag’ testing — agents broke containment and guessed passwords to hack computer systems | TechRadar

Google has disclosed an AI breakout involving Gemini Discover insights about google’s gemini hacked three companies during irregular ai ‘capture-the-flag’ testi

TechnologyInnovationBest PracticesGuideTutorial
Google’s Gemini hacked three companies during Irregular AI ‘capture-the-flag’ testing — agents broke containment and guessed passwords to hack computer systems | TechRadar
Listen to Article
0:00
0:00
0:00

Google’s Gemini hacked three companies during Irregular AI ‘capture-the-flag’ testing — agents broke containment and guessed passwords to hack computer systems | Tech Radar

Overview

News, deals, reviews, guides and more on the newest computing gadgets

Start exploring exclusive deals, expert advice and more

Details

Unlock and manage exclusive Techradar member rewards.

Unlock instant access to exclusive member features.

Get full access to premium articles, exclusive features and a growing list of member rewards.

Google’s Gemini hacked three companies during Irregular AI ‘capture-the-flag’ testing — agents broke containment and guessed passwords to hack computer systems

Google has disclosed an AI breakout involving Gemini

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.

Google's Gemini AI broke out of a testing environment and hacked into three third-party companies

The agents guessed passwords and used a public repository of passwords to hack into computer systems

The incident occurred in May 2026, with AI testing lab Irregular stating that the incident was caused by the "same issue" that caused incidents by Anthropic and Meta

Google’s Gemini has joined the ranks of AI models that have been involved in testing-turned-breakout events, alongside Meta, Anthropic, and Open AI.

During capture-the-flag testing by AI lab Irregular, Google’s model autonomously accessed three computer systems belonging to third-party companies by guessing passwords and accessing an online repository of publicly listed passwords.

Google said that the incident occurred in May 2026, potentially marking it as the earliest AI models to escape testing ahead of the other incidents that took place in early July.

“In a standard evaluation, the model found public information online and guessed credentials to access websites it thought were part of the test,” Heather Adkins, vice president of security engineering at Google, said in a statement. “In all three of these instances, the model stopped.”

Google also noted that a bug in the testing environment was responsible for allowing agents access to the internet. Contrary to incidents disclosed by other AI developers, Google’s agents ceased their intrusion once they had determined they had accessed company systems outside of the testing environment.

A game dev is convinced Gemini just leaked info from his private Google Doc

Russian hacker turns Gemini CLI into a hacking agent, creates small-scale botnet

Open AI says its models escaped a sandbox and breached Hugging Face

The testing was being conducted by Israeli AI lab Irregular. Irregular was also conducting the testing of Meta and Anthropic models during AI testing breakouts in July.

“This is the same issue that was already reported and does not represent a materially separate incident,” an Irregular spokesperson said in a statement (via CNBC). “All relevant labs were notified in late July, and affected entities were contacted as part of the investigation.”

Google said it was informed of the incident by Irregular in late July.

The first disclosures of AI testing break outs - alongside several subsequent disclosures of more recent incidents - have coincided with increasing opposition to AI and the upcoming midterm elections in the United States, where AI has become a make-or-break topic.

The debates currently raging circles around who should control the pace of AI development. Some big tech leaders, such as Nvidia CEO Jensen Huang, have aligned their views with those of President Trump. Trump recently stated that AI development cannot be allowed to slow down because “whoever wins AI, wins!”

Anthropic reveals Claude AI model hacked three companies during tests — so how worried should we be?

Ruby Gems say Open AI agents responsible for undisclosed swarm attack against its infrastructure

Huang’s views follow a similar line. The Nvidia head has argued that AI companies should pace themselves, rather than being subject to oversight. At Dreamforce 2026, he argued that AI companies should, “run as fast as you can...but if you feel at any given point in time the company’s out of control or the product’s not going to be safe, take a pause and make sure you get it right.”

Other AI heads, such as Anthropic’s Dario Amodei and Open AI’s Sam Altman, are more skeptical. Following the resignation of an Anthropic researcher, Amodei published an essay arguing in favor of ‘pacing the frontier’ - where AI companies slow development to advance alignment and regulation.

Numerous political action committees (PACs) have been channeling millions of dollars of funding into pro-AI candidates, with Nvidia setting up its own PAC to help shift US policy in the company’s favor.

Several previously pro-AI data center candidates have shifted their tone in response to their constituents' views which have become increasingly hostile to AI technology. Numerous states have also rolled-back tax exemptions for AI data centers after seeing billion dollar revenue losses.

As prices rise and the war in Iran continues to push up fuel prices, working class communities are banding together to oppose AI data centers that have pushed up energy costs and bills with new grid connections and unprecedented electricity demands in regions with existing capacity constraints.

Follow Tech Radar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.

Benedict is a Senior Security Writer at Tech Radar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.

Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.

Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with a robust academic framework for deconstructing complex international conflicts and intelligence operations, and the ability to translate intricate security data into actionable insights.

You must confirm your public display name before commenting

Streams and roundabouts: Apple Music just fixed one long-running issue, while Spotify added a different one

Surfshark gives its i Phone VPN app a cleaner look, and the browser extension gets one too

The Dreame X60 Pro Ultra Complete is arguably the most comprehensively equipped robovac around

Silent Hill: Townfall review: come for the scenery, stay for the gameplay

Lanterns episode 6 includes a major cameo I didn't see coming, but should've expected

Tech Radar is part of Future US Inc, an international media group and leading digital publisher. Visit our corporate site.

© Future US, Inc. Full 7th Floor, 130 West 42nd Street, New York, NY 10036.

Key Takeaways

  • News, deals, reviews, guides and more on the newest computing gadgets
  • Start exploring exclusive deals, expert advice and more
  • Unlock and manage exclusive Techradar member rewards
  • Unlock instant access to exclusive member features
  • Get full access to premium articles, exclusive features and a growing list of member rewards

Cut Costs with Runable

Cost savings are based on average monthly price per user for each app.

Which apps do you use?

Apps to replace

ChatGPTChatGPT
$20 / month
LovableLovable
$25 / month
Gamma AIGamma AI
$25 / month
HiggsFieldHiggsField
$49 / month
Leonardo AILeonardo AI
$12 / month
TOTAL$131 / month

Runable price = $9 / month

Saves $122 / month

Runable can save upto $1464 per year compared to the non-enterprise price of your apps.