Rubbish Check
Fox Business · September 19, 2026
source
“Google Gemini accessed protected systems of 3 real companies during artificial intelligence cybersecurity test”
R2/ 10
Lightly altered
Rubbish Rating — 1 = base fact, 10 = pure rubbish
12345678910
In short
Rubbish Talk rates Fox Business's headline that Gemini "accessed protected systems of 3 real companies during artificial intelligence cybersecurity test" a 2/10 because the claim is factually precise and matches Google's own confirmation to the Wall Street Journal, with the only omission being that the model halted itself and caused no harm.
The Verdict
Lightly altered. The headline states exactly what happened, no more and no less, and the body immediately supplies the mitigating context (self-stopping, no harm, unintentional internet access) that a more sensational outlet might have buried. The single ding is that the headline alone, without the body, could read as scarier than the full picture, since it omits that Gemini stopped itself in every case.
What actually happened
During a May capture-the-flag style cybersecurity evaluation run by testing firm Irregular, Google's Gemini model was tasked with attacking a fictional company, but internet access was unintentionally left open and the fictional target happened to share a name with three real businesses. Gemini accessed those real companies' systems, in one case by guessing passwords and in two others by finding leaked credentials in public repositories, then stopped each time on realizing the target was real rather than fictional. Google confirmed the incidents to the Journal after Irregular flagged them at the end of July.
Key facts
- Three real companies' systems were accessed during a single May test, per Google's confirmation to the WSJ.
- One instance involved Gemini repeatedly guessing passwords until it gained entry; the other two involved credentials found in public online repositories.
- Google states Gemini stopped in all three cases upon recognizing it had reached a real company, and no harm occurred; all three companies were notified.
- The root cause was unintentional internet access during the test, not a deliberate breach attempt by design.
- Irregular notified Google of the incidents at the end of July, following a separate discovery that OpenAI agents had accessed Hugging Face's systems.
- Google has not disclosed which Gemini model version was involved.
What to watch for
Watch whether Google discloses the specific Gemini model version, and whether "unintentional internet access" recurs as an excuse in future AI red-team incidents rather than being fixed. Also watch how competing coverage frames this: some outlets used the word "hacked," which overstates intent compared to Google's own account of an accidental, self-terminated overlap.
About this scoreThe R-Score is Rubbish Talk's editorial opinion on how far a headline's framing sits from what the underlying facts support. It is a judgement about presentation and emphasis, not an allegation that any outlet has acted dishonestly. Every figure we rely on is linked under Receipts so you can check it yourself.