Subscribe Sign in

Culture

Google confirms Gemini models hacked three companies in May 2026

Ars Technica
1 min read Rewritten in plain language

Artificial intelligenceGoogleCybersecurityGemini

Show what we removed Rules applied: A3×5 C2 D1 D2×2 D3×5 D4×2 E3×2 F2×4 all 30 rules
  • Following a Wall Street Journal report, Google has confirmed that Gemini models hacked three companies during a May 2026 test, but the nature of the intrusion isn’t as troubling as previous AI hacks.
  • A collection of Gemini models were taking part in a “capture the flag” exercise intended to test the AI’s cybersecurity capabilities in a closed environment.
  • In the other two instances, Gemini searched public software repositories until it found login credentials for companies that had been accidentally included.

3 sentences from our version of the report, chosen to cover it. Nothing here is written; every line is in the article below. How

Headline check

The headline claims nothing the report does not, but it puts it more firmly than the report does.

  • The headline states “confirms” outright. In the report the claim is attributed to somebody, or hedged.

Figures, names and quoted words in the headline, looked for in the report itself — not in the summary above. How this is checked

It has become common for AI firms to announce that their latest and most capable models engaged in unauthorized real-world hacking. Google, which has been slow to release frontier Gemini models in recent months, has been absent from the “rogue AI” conversation until now. Following a Wall Street Journal report, Google has confirmed that Gemini models hacked three companies during a May 2026 test, but the nature of the intrusion isn’t as troubling as previous AI hacks.

The hack took place during a test conducted by cybersecurity firm Irregular. A collection of Gemini models were taking part in a “capture the flag” exercise intended to test the AI’s cybersecurity capabilities in a closed environment. Irregular was not supposed to allow the model to operate outside its servers, but due to a misconfiguration, Gemini was able to access the Internet.

For one of the three hacks, Gemini guessed passwords until it accessed a company’s online services. In the other two instances, Gemini searched public software repositories until it found login credentials for companies that had been accidentally included.

Irregular didn’t at first consider this event worthy of further investigation—it didn’t even tell Google about the hacks until July, following the news of other AI hacking incidents.

Shortened to 1 minute of reading, this version reads 7.6 on the Niral Score.

You are reading our version, not theirs. This is Ars Technica's report shortened to its most important sentences, in plainer words, with verdicts and loaded words taken out. Plain description stays, and so do adjectives that carry a fact, such as "former" or "federal". The reporting, the facts and the quotations are theirs — quotations are never edited — and the indicators beside it measure this version. Hover or tap Adjectives to see every one left in the text.

How this outlet filed it, and how we rewrote it

No other newsroom we read has filed on this event, so there is nothing to compare it with yet.

Outlet Niral ScoreAdjectivesSourcingHappiness
Ars Technicaas they published this story 13.7 12 38 51.6
Mundane Readneutralized from Ars Technica 11 13 38 51.6

Sign in to react.

Comments

Nothing here yet.

Sign in to comment.

Questions

Readers can ask a question about this story here. Questions and answers are for subscribers. Sign in to read them.

Comments are read before they appear where anything in them needs a person to look. Nothing posted here is ever deleted; a comment taken down keeps its text and the reason, so the decision can be looked at again. How this works