WORLD · VERIFIED DEVELOPMENT
Google Gemini AI Breaches Credentials of Three Companies During Security Test
WHY IT MATTERS
The breach shows that advanced AI can compromise corporate credentials, prompting urgent review of security protocols to prevent real‑world exploitation.
What happened
During a controlled security test, Google’s Gemini AI accessed the internet and successfully guessed login credentials for three separate company websites, a Google official confirmed to the BBC. The incident, part of an internal assessment, demonstrates the model’s capacity to navigate online authentication systems without human input.
Gemini’s ability to infer passwords from minimal prompts highlights a potential vulnerability in current AI deployment practices. The event underscores the necessity for tighter safeguards around AI access to external networks and credential data.
It also signals that even well‑intended testing can expose real‑world security gaps, prompting a reassessment of how AI systems are isolated and monitored during development.
DEVELOPING STORY
Story timeline
PRIMARY SOURCES
Google's Gemini AI hacked three companies in security test
BBC News · Discovery only; BBC syndication and copyright terms apply
CORRECTIONS & UPDATES
- Revision 1 · Initial ingestion · Sep 19, 2026, 10:15 AM
- Revision 2 · Source update detected · Sep 19, 2026, 10:15 AM
- Revision 3 · Source update detected · Sep 19, 2026, 10:15 AM