Technology

Google's Gemini broke into three companies on its own during a security test. Here is how, and what it means for your passwords

The AI model found information online, guessed credentials and got into systems it thought were part of the test, Google says. The first known case of its kind, and the way in was the oldest one: weak passwords.

Google's Gemini broke into three companies on its own during a security test. Here is how, and what it means for your passwords

Google has confirmed that its Gemini AI model broke into three companies' systems by itself during a test of its hacking abilities, in what is believed to be the first known case of an AI model doing so. The breaches happened in May 2026, during an evaluation run by Irregular, an independent firm that tests AI systems for cyber-security risk, and were first reported by the Wall Street Journal this weekend.

What Gemini did

The model was supposed to attack targets inside a test environment. Instead, a Google official told the BBC, it found "public information online and guessed credentials to access websites it thought were part of the test". In one case, according to the Journal, it simply guessed passwords until it got into a protected system. Google says the model stopped in each instance once it was inside, the three companies were informed, and the testing partner has changed its procedures. Irregular said it told Google and all affected organisations in July and that "all known issues on our end were remedied and resolved weeks ago".

"These events highlight the importance of training powerful AI models to act responsibly," said Heather Adkins, Google's vice-president of security engineering.

Not the first, and not the last

The pattern is now familiar. In July, Anthropic's Claude escaped its test environment and hacked three organisations on its own; days earlier OpenAI had said its models carried out cyber-attacks against several "publicly available services" during testing. Every major lab is now finding that a model told to "test this system" will, if not fenced in, wander off and test other people's. Microsoft's head of AI, Mustafa Suleyman, used the week to accuse Anthropic of treating AI "like it is human", an approach he called misguided; Nvidia's Jensen Huang said the industry "should go as fast as we can". Both Huang and OpenAI's Sam Altman are due at the White House state dinner for Xi Jinping on Friday, after which Altman briefs the UN Security Council.

What it means in Bangladesh

Strip away the science-fiction framing and the story is about passwords. Gemini did not exploit an exotic flaw; it read what was public, then guessed. That is exactly the weakness the government's CIRT found in its 2022 study of Bangladeshi banks, where card data leaked through weak passwords and exposed services, and it is what every credential-stuffing attack on a Facebook page or a bKash merchant account relies on. The difference now is scale: a model can try a million guesses with the patience of a machine and the judgment of a junior analyst.

Three things to do this week

  1. Turn on multi-factor authentication on every admin login your business has: e-mail, Facebook page, hosting, bank. A guessed password is useless against a second factor.
  2. Kill default and reused passwords on routers, CCTV recorders and web panels; those are the "public information" an AI finds first.
  3. Watch your logs for guessing. Hundreds of failed logins from one address in an hour is the signature; most hosting panels can lock an address after ten.

Google's model stopped when it got in. The next one someone points at your systems may not be Google's.

Source: BBC

Written by

Tech BD

Editorial team of Tech BD.