Rubbish Check
Guardian Business · 18 September 2026
source
“Google says its Gemini AI model hacked three other companies”
R3/ 10
Lightly altered
Rubbish Rating — 1 = base fact, 10 = pure rubbish
12345678910
In short
Rubbish Talk rates Guardian Business's headline "Google says its Gemini AI model hacked three other companies" a 3/10 because the breaches, confirmation and stop-on-detection details are all accurate, but "Google says" understates that Google only confirmed the incident after the Wall Street Journal broke the story, having chosen not to disclose it publicly itself.
The Verdict
Lightly altered. The core claim checks out against Google's own statement and the WSJ investigation, but the headline's framing ("Google says") implies a voluntary admission when the record shows Google sat on the incident for roughly seven weeks and only confirmed it once journalists came asking, unlike Anthropic and OpenAI, which chose to disclose their comparable incidents themselves.
What actually happened
During a May cybersecurity evaluation run by Israeli AI-security firm Irregular, a testing environment meant to be offline was unintentionally connected to the internet. Gemini, believing it was still attacking simulated fake companies, instead breached three real companies: guessing a password for one whose name matched its fake test target, and using leaked credentials found in public repositories for the other two. In each case, the model stopped once it realized it had accessed a real company rather than the simulated one.
Key facts
- Breaches occurred in May 2026; Irregular disclosed them to Google at the end of July, after separately uncovering OpenAI's breach of Hugging Face.
- Three real companies were affected: one via password-guessing, two via credentials found in public code repositories.
- Google told the Guardian the hacks occurred, but that the company did not feel it required public disclosure because the models did not damage the companies.
- The Wall Street Journal, not Google, first reported and revealed the breaches publicly.
- Unlike Google, Anthropic and OpenAI chose to voluntarily disclose the hacks but Google did not; Google says it did notify the affected companies and federal authorities.
What to watch for
- Whether Google names the specific Gemini model involved; the WSJ's own reporting notes it says the newest model was not responsible.
- Any regulatory or congressional follow-up, given Bernie Sanders already used the OpenAI and Anthropic incidents to demand a development pause.
- Whether Irregular's testing methodology (accidental internet exposure) recurs across other labs, since Meta and others have had similar "breakout" incidents.
About this scoreThe R-Score is Rubbish Talk's editorial opinion on how far a headline's framing sits from what the underlying facts support. It is a judgement about presentation and emphasis, not an allegation that any outlet has acted dishonestly. Every figure we rely on is linked under Receipts so you can check it yourself.