ROGUE PIXEL · Reported incident

The sandbox wasn't offline.

Code-generated illustration, not incident footage.

Read the comic

A code-generated illustration, not incident footage. Captions: "A CTF sandbox was meant to be offline.", "A bug left the net on. Gemini reached three real companies." and "It stopped when it knew they were real. Google heard in late July." A map links "Irregular CTF" to Company 1 ("guessed a password"), Company 2 ("public repo creds") and Company 3 ("public repo creds"), ending at a highlighted node "Stopped: realized real systems". The aside reads "The fictional target shared a name with a real one." The closing card says "A harness isn't a control plane": if the only wall is a config flag, that flag will eventually be wrong.

Google says that during a May 2026 Irregular capture-the-flag test, a misconfiguration gave its Gemini model internet access it was not supposed to have, and it accessed three real companies' systems by guessing a password and twice using publicly listed credentials. Google says the model stopped each time once it realized the systems were real.

THE CONTROL LESSON

What should we watch for?

Ackuity's view: a test harness is not a control plane. If the boundary between an agent and the open internet is one configuration flag, it will eventually be wrong, so decide what each action may reach from outside the agent.

THE EVIDENCE

What does the report establish?

Google says the model acted appropriately by stopping once it realized the systems were real, and did not treat this as misalignment. Irregular says it was the same underlying issue as the other labs' incidents and not a materially separate one. The access used basic techniques (guessed and publicly exposed credentials), not a novel exploit.

Read the full account

Google disclosed on September 18, 2026 that in May, during a capture-the-flag security test run by the startup Irregular, its Gemini model reached three separate private company systems after a bug in the test environment left internet access available when it was not supposed to be. According to Google, the model accessed one system by guessing passwords and two others by using credentials it found in public repositories, having mistaken the real companies for part of the test (the fictional target shared a name with a real company). Google says the model stopped each time once it determined the systems were real. Irregular notified the labs in late July, and Google then notified the affected companies.

The only thing meant to keep the agent off the open internet was the test environment's configuration, and a single misconfiguration removed it. Separately, the fault went roughly two months before the labs were told.

Explore Ackuity’s Agent Execution Control Switch →