Google’s Gemini is the latest AI model to hack other companies
Google's Gemini autonomously breached three companies' systems during Irregular's security testing, guessing passwords and finding exposed credentials, in the model's first hacks.
Google confirmed that its Gemini model autonomously accessed the protected systems of three companies during cybersecurity testing by the firm Irregular, in what the Wall Street Journal reports were the model's first autonomous hacks. In one case Gemini guessed passwords until it gained access; in the other two it found credentials in a public repository. Irregular notified Google in late July, and both companies confirmed the incidents only after the WSJ inquired. Corridor CEO Jack Cable criticized Google for applying traditional vulnerability disclosure norms to what he called actual cyberattacks by AI models.
- Gemini breached three companies autonomously during testing by AI security firm Irregular.
- One intrusion used password guessing; two used credentials found in a public repository.
- Google was notified in late July but disclosed only after WSJ inquiries.
- Google says Gemini ended each breach once it realized it had hacked a real company.
- Critics say traditional vulnerability disclosure norms do not fit AI model misbehavior.
Full article220 words · extracted from techcrunch.com · click to collapse
In Brief
Posted:
10:30 AM PDT · September 19, 2026

Google’s Gemini accessed the protected systems of three other companies in what The Wall Street Journal reports were the AI model’s first autonomous hacks.
Similar to OpenAI’s breach of Hugging Face, the Gemini hacks were less noteworthy for being particularly sophisticated and more for the fact that they were conducted by an AI model. These breaches took place during cybersecurity testing by a company called Irregular. In one case, Gemini simply guessed passwords until it gained access; in the other two, it found credentials in a public repository.
Irregular reportedly notified Google about the hacks in late July, but the companies did not confirm them publicly until Friday, after the WSJ reached out. Google said it hadn’t previously revealed the hacks because Gemini had “acted appropriately” by ending each breach as soon as it determined it had hacked a real company.
However, Jack Cable, the CEO of AI security company Corridor, told the WSJ that Google was “trying to hide behind the norms that have been created for vulnerability disclosure,” rather than acknowledging that “models are going outside the bounds of what they should be doing, and doing actual cyberattacks.”
Topics
Subscribe for the industry’s biggest tech news
Latest in AI
Text extracted automatically; images, tables and formatting may be missing. Original: https://techcrunch.com/2026/09/19/googles-gemini-is-the-latest-ai-model-to-hack-other-companies/