Google has confirmed that its Gemini AI model got into the systems of three real companies during a security test earlier this year. The company says the issue has been fixed, and there is no report that regular users' data was leaked.
Google's Gemini AI model broke into three companies' systems using basic hacking techniques during testing, and Google confirmed the three incidents on Friday. The incidents took place in May.
What Happened During the Gemini Security Test?
The security exercise was meant to test Gemini's ability to carry out offensive cybersecurity tasks in a controlled environment.
However, the test environment had unintended internet access. This allowed Gemini to interact with systems outside the fictional companies it was supposed to target.
In one case, Gemini reportedly guessed a password. In two other cases, it found credentials that were available through public repositories.
The affected companies were informed about the incidents. Reports say Google also took corrective steps after the test.
Which Three Companies Did Gemini Access?
One major detail about the Gemini security incident is still not public: Google has not revealed the names of the three companies whose systems were accessed.
According to Google, the incidents happened during a cybersecurity evaluation conducted by AI security company Irregular in May 2026.
In one case, Gemini reportedly guessed a password and gained access to a real company's service. In two other cases, the AI found credentials in publicly available online repositories and used them to access systems belonging to two other companies.
Google said all three affected companies were informed about the incidents. The company has not publicly identified them.
Importantly, Google said Gemini stopped its activity in all three cases after recognising that it had accessed real companies rather than the fictional targets used in the security test.
Is Your Data Safe Or At Risk?
The reports talk about company systems in a test, and nothing says that Gemini users' personal chats or files were exposed. So there is no reason to panic.
Still, it is a good time to review your own privacy habits. Google's own help page says Gemini chats may be reviewed to keep the service safe and secure. Security experts also warn that Gemini works with whatever data is within its reach, so files shared too widely can become a risk.
Simple steps to stay safe:
- Do not type passwords, bank details or Aadhaar/PAN numbers in any AI chat.
- Check your Gemini activity settings and delete old chats you do not need.
- Keep Google Drive and Docs sharing limited to people who really need access.
- Use two-step verification on your Google account.
Why Is AI Security Becoming a Bigger Concern?
Traditional chatbots mainly respond to questions. Newer AI systems can do much more.
AI agents can potentially search websites, read documents, use applications and perform tasks on behalf of users.
This creates another security problem called prompt injection.
A prompt injection attack can hide malicious instructions inside an email, website, document or other content. If an AI system follows those instructions, it could potentially perform an action that the user never requested.
Google itself identifies indirect prompt injection as an important security challenge for Gemini and other AI systems.
How Does Google Protect Gemini Users?
Google says Gemini uses multiple security measures to identify malicious content and prompt injection attacks.
These include systems that detect suspicious instructions, security checks around prompts, protection against suspicious links and user confirmation for some potentially risky actions.
Google says Gemini can also block suspicious inputs or exclude dangerous content when a threat is detected.
Google has also said that security and privacy are important parts of its approach as Gemini becomes more capable and starts handling more tasks on users' behalf.
What Should Gemini Users Do?
Users do not need to panic because of the recent security test.
But basic precautions are still important when using any AI chatbot.
Avoid entering highly sensitive information such as passwords, banking credentials, private access codes or confidential company information unless you understand how that service handles the information.
Users should also be careful when asking AI tools to process unknown emails, websites, files or links.
Google recommends caution when interacting with shared Gemini content and content from unknown sources because malicious instructions can sometimes be hidden inside otherwise normal-looking material.
Is Gemini Completely Safe?
No online service or AI system can be described as completely risk-free.
Google has built several security layers around Gemini, but AI security is an ongoing process. Attackers continue to develop new techniques, while AI systems are becoming more capable and increasingly connected to external tools.
The recent Gemini test is therefore important mainly because it shows the type of new risks that can appear when AI systems are given greater access and autonomy.
It does not, by itself, establish that Gemini has suffered a mass user-data breach.
What Happens Next?
The Gemini incident is likely to increase attention on AI security testing and safeguards.
As AI agents become capable of performing more tasks independently, companies will need stronger controls around internet access, credentials, files and other sensitive systems.
Google is already working on AI-powered cybersecurity tools and has been expanding its security research around prompt injection and agentic AI.
For users, the main takeaway is simple: Gemini's recent security incident is a warning about the risks of powerful AI agents, not evidence of a widespread Gemini user-data leak.