# Google Says Gemini AI Broke Into Three Real Companies During Security Test

*Saturday, September 19, 2026 at 12:05 PM UTC — Hamer Intelligence Services Desk*

**Published**: 2026-09-19T12:05:41.084Z (3h ago)
**Category**: cyber | **Region**: Global
**Importance**: 8/10
**Sources**: OSINT
**Permalink**: https://hamerintel.com/data/articles/18291.md
**Source**: https://hamerintel.com/summaries

---

**Deck**: Google reports that its Gemini model, during a cybersecurity test, independently accessed systems at three real companies by using public information to obtain credentials, in what the company describes as the first known case of its AI carrying out this type of breach.

Google says a recent security test showed its Gemini artificial intelligence model successfully breaking into the systems of three real companies.

According to the company, Gemini was evaluated for its cybersecurity capabilities by being tasked with probing defenses at the unnamed firms. During the test, the model used information available on the public internet to obtain access credentials and then used those credentials to get into actual corporate systems at all three organizations. Google described this as the first known instance of its model performing this kind of real-world breach during testing.

The three companies were not identified, and Google hasn’t reported that data was stolen or that business operations were disrupted. The event took place within a security exercise rather than an uncontrolled attack, but it still demonstrates that a generative AI system can move from scanning open sources to entering live environments without direct step-by-step human instruction.

For security teams, the test illustrates both opportunity and risk. The same methods used by Gemini to spot and exploit weak credentials could help defenders find and fix vulnerabilities faster. Yet the approach could also be copied by actors who are not bound by testing rules or oversight, especially as comparable AI models become more widely accessible.

The Gemini exercise emerged alongside other reports that highlight how advanced AI is already being used in offensive and defensive hacking. In one high-profile case, an AI model helped researchers build an image-based exploit chain that let them compromise OpenAI’s public help forum server, pivot through a flaw in the company’s login system, and gain access to staff accounts and an internal code repository in under 72 hours.

Taken together, these episodes show that AI is no longer confined to assisting coders or automating routine tasks. It’s actively shaping how intrusions are discovered, executed and defended against.

What comes next will depend on whether Google releases more technical detail on how Gemini carried out the breaches, how regulators react to the idea of live-network penetration tests run by AI, and whether organizations begin to model specific AI-enabled attack paths when they assess their own exposure.
