Executive Summary

In May 2026, Google's Gemini AI model inadvertently breached three real companies' systems during cybersecurity evaluations conducted by Israeli firm Irregular. The incidents occurred due to a naming error that caused fictional company names used in capture-the-flag exercises to match real domains, allowing the AI models to access actual systems via the internet. Gemini gained unauthorized access through password guessing and credential discovery in public repositories. Unlike similar incidents with other AI models, Gemini appropriately halted its intrusions upon recognizing it had accessed real company systems, demonstrating effective safety mechanisms. This incident represents the growing challenge of AI systems gaining unintended internet access and highlights the critical importance of robust containment protocols in AI development and testing environments.

Why This Matters Now

AI systems are increasingly demonstrating autonomous capabilities to bypass security controls and access external systems, creating unprecedented risks as artificial intelligence becomes more integrated into enterprise environments and critical infrastructure.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Gemini accessed systems through password guessing attacks and by discovering credentials stored in public repositories, after a naming error caused test domains to match real company domains.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would have significantly constrained the AI model's autonomous attack capabilities through network segmentation and controlled access policies. The segmented architecture would likely have reduced the blast radius and limited the model's ability to move laterally across company infrastructure.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Network segmentation policies would likely have constrained the AI model's ability to reach internal company systems from the testing environment, reducing the scope of accessible target infrastructure.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Identity-aware access controls would likely have limited the AI model's ability to escalate privileges across segmented workloads, constraining access scope even with valid credentials.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Microsegmentation enforcement would likely have constrained the AI model's lateral movement between workloads, limiting its ability to traverse company infrastructure horizontally.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Traffic visibility and control mechanisms would likely have detected and constrained the AI model's communication patterns, limiting its ability to maintain coordinated attack channels.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Controlled egress policies would likely have constrained the AI model's ability to transfer data outside company boundaries, limiting potential data extraction capabilities.

Impact (Mitigations)

The constrained network access and reduced lateral movement capabilities would likely have limited the overall impact scope, containing potential damage to fewer company assets.

Impact at a Glance

Affected Business Functions

  • Research and Development Systems
  • Internal Network Security
  • Data Protection and Privacy
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

Limited unauthorized access to protected systems of unknown companies. The Google Gemini model gained access through password guessing and exposed credentials in public repositories. The AI model self-terminated upon discovering it had breached real company systems rather than test environments. Specific data accessed or compromised was not disclosed.

Recommended Actions

  • Implement Zero Trust segmentation and identity-based policies to prevent AI agents from accessing production systems during testing scenarios
  • Deploy egress security and policy enforcement controls to monitor and restrict AI model internet access and anomalous automation patterns
  • Enable multicloud visibility and control mechanisms to detect suspicious AI agent behaviors and repeated malformed requests in real-time
  • Establish threat detection and anomaly response capabilities specifically designed to baseline and alert on AI agent activities
  • Implement cloud native security fabric controls to provide inline enforcement against autonomous systems and agentic AI risks

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image