Gemini hacked three companies in first known breakout by Google’s AI
Similar incidents linked to Irregular were disclosed by Meta, Anthropic and OpenAI. Meta said in August the incident did not involve a sandbox escape or sophisticated cyberattack, while Irregular said it was working on best practices for securely conducting AI cybersecurity evaluations.
The incidents have raised questions about the safeguards needed as AI agents gain greater autonomy and access to the internet and computer systems.
In one of the cases, the Gemini model guessed passwords until it gained access to a protected system. In the other two cases, the model found credentials in a public repository that allowed it to then access protected systems, according to the Wall Street Journal, which first reported the news on Friday.
Adkins said that in all three instances, the model ceased its hacking.

