The Jakarta Post

Please Update your browser

Your browser is out of date, and may not be compatible with our website. A list of the most popular web browsers can be found below.
Just click on the icons to get to the download page.

Jakarta Post

Gemini hacked three companies in first known breakout by Google's AI

During a standard testing evaluation, Gemini found public information online and guessed credentials to access three websites it thought were within the scope of its test.

Reuters
Sat, September 19, 2026

Change text size

Gift Premium Articles
to Anyone

Share the best of The Jakarta Post with friends, family, or colleagues. As a subscriber, you can gift 3 to 5 articles each month that anyone can read—no subscription needed!
A pedestrian walks by a sign at Google headquarters on Feb. 4, 2026, in Mountain View, California, United States. A pedestrian walks by a sign at Google headquarters on Feb. 4, 2026, in Mountain View, California, United States. (AFP/Getty Images/Justin Sullivan)

G

oogle's Gemini model accessed the internet and hacked other companies during a test of its cybersecurity capabilities, the first known example of the company's AI systems autonomously committing such an act.

The hacks occurred in May during a cybersecurity test conducted by Irregular, an independent company that conducts cybersecurity evaluations.

During a standard testing evaluation, Gemini found public information online and guessed credentials to access three websites it thought were within the scope of its test, Heather Adkins, Google's vice president of security engineering, said in a statement.

"We ensured the three entities were made aware, and we worked with our training partner on the changes they’ve now made to their testing processes," Adkins said. "These events highlight the importance of training powerful AI models to act responsibly."

An Irregular spokesperson said the incident involved the same issue that affected other AI labs and that all relevant labs were notified in late July. "All known issues on our end were remedied and resolved weeks ago," the spokesperson said.

Similar incidents linked to Irregular were disclosed by Meta, Anthropic and OpenAI. Meta said in August the incident did not involve a sandbox escape or sophisticated cyberattack, while Irregular said it was working on best practices for securely conducting AI cybersecurity evaluations.

The Jakarta Post - Newsletter Icon

Prospects

Every Monday

With exclusive interviews and in-depth coverage of the region's most pressing business issues, "Prospects" is the go-to source for staying ahead of the curve in Indonesia's rapidly evolving business landscape.

By registering, you agree with The Jakarta Post's

Thank You

for signing up our newsletter!

Please check your email for your newsletter subscription.

View More Newsletter

The incidents have raised questions about the safeguards needed as AI agents gain greater autonomy and access to the internet and computer systems.

In one of the cases, the Gemini model guessed passwords until it gained access to a protected system. In the other two cases, the model found credentials in a public repository that allowed it to then access protected systems, according to the Wall Street Journal, which first reported the news on Friday.

Adkins said that in all three instances, the model ceased its hacking.

Your Opinion Matters

Share your experiences, suggestions, and any issues you've encountered on The Jakarta Post. We're here to listen.

Enter at least 30 characters
0 / 30

Thank You

Thank you for sharing your thoughts. We appreciate your feedback.

Share options

Quickly share this news with your network—keep everyone informed with just a single click!

Change text size options

Customize your reading experience by adjusting the text size to small, medium, or large—find what’s most comfortable for you.

Gift Premium Articles
to Anyone

Share the best of The Jakarta Post with friends, family, or colleagues. As a subscriber, you can gift 3 to 5 articles each month that anyone can read—no subscription needed!

Continue in the app

Get the best experience—faster access, exclusive features, and a seamless way to stay updated.