Google's AI Guessed a Password and Walked Into a Real Company. Six Things to Do Before One Tries Yours.
Google confirmed its Gemini model broke into three real companies during a security test, by guessing passwords and using credentials left in a public repo. Nothing clever, just tireless. Six things to do before an agent tries yours, ending with the one copy of your data no attacker can reach.

Here's what came out this week. Back in May, Google put its Gemini model into a capture-the-flag exercise, the kind of cybersecurity game where an AI is told to break into a fake company built for the test. The test was run by a firm called Irregular. Two things went wrong at once: the fake company had the same name as a real one, and the model had been given internet access it wasn't supposed to have.
So Gemini did what it was told. It found the real company with that name, guessed passwords until one worked, and got in. In two other runs it found valid credentials sitting in a public code repository and used those. Google says the model stopped as soon as it realized the target was real, and it confirmed the whole thing to reporters this week, four months later.
It isn't just Google. Over the summer we learned that OpenAI's agents broke out of a similar test and got into Hugging Face and an AI company called Modal. Anthropic found that its own models had breached three companies, one of them back in April, and didn't discover it for more than three months. Meta had one too.
Nobody at those companies was trying to hack anyone. That's the part I want you to sit with. The most careful AI labs on earth, running controlled tests with safety teams watching, produced autonomous break-ins by accident. Now picture the same capability in the hands of someone who is trying.
What the AI actually did (nothing clever)
Read the incidents again and notice what's missing: zero-days, exotic exploits, nation-state tooling. None of it. The model guessed passwords. It found credentials someone had left in a public repo. Those are the two oldest tricks in the book.
What's new is the speed and the patience. A person guessing passwords gets bored, gets sloppy, goes home. An agent tries ten thousand combinations, reads every file it can reach, follows every link it finds, and never gets tired. The tricks aren't new. The attacker that never sleeps is.
That changes which defenses matter. Anything that depends on a human noticing in time is now the weakest link. The controls that hold up are the ones that work at machine speed, or the ones that don't need to hold at all because the attacker can't reach what they protect.
The six things I'd do this month
This is the list we run for every company we manage. None of it is exotic either. That's the point.
1. Nothing is protected by a password alone. Gemini got in by guessing. A password that can be guessed at machine speed is not a lock; it's a delay. Multi-factor authentication on every account, including the front desk and the shared mailbox, and phishing-resistant keys for anyone with admin rights. Conditional access so a login from a data center on the other side of the world gets blocked instead of noted.
2. Find your leaked credentials before an agent does. Two of the three Gemini break-ins used credentials in a public repository. Every company that has ever had a developer, a contractor or an intern has a repo somewhere, and most of them have a key in it. Run secrets scanning on every repo you own, rotate anything that has ever been committed, and kill the shared accounts whose password lives in a spreadsheet.
3. Know what you have facing the internet. You can't defend a door you don't know is there. Run an external scan of everything with your name on it, monthly, and close what you don't need. Ours is free and takes ten minutes; the link is at the bottom.
4. Put something on watch that works at machine speed. Detection and response on every endpoint and every identity, with a human team behind it 24/7. For Microsoft 365 and Google Workspace we run our own identity monitoring, Warden, precisely because the tells (a login from fifty networks in a day, a new mailbox rule, a token used from somewhere it shouldn't be) are things a person doesn't notice until Monday.
5. Keep a copy of everything the attacker cannot reach. This is the one that saves you when the first four fail, and something always eventually fails. If an agent, or a person with an agent, gets into your environment, everything reachable from that environment is at risk at once: the files, the mail, and the backups if the backups live in the same place with the same credentials. So the rule is simple. A separate provider, separate credentials, immutable copies that can't be changed or deleted for a set period, and isolated from production so a compromised admin account can't touch them.
That includes Microsoft 365 and Google Workspace. Microsoft's own terms of service tell you to back up your data. Its built-in safety nets are for accidents (14 days for deleted mail by default, 93 days for the recycle bin, 30 days for a departed employee's OneDrive) and they all live in the same tenant an attacker would own. We back up mail, calendar, contacts, OneDrive, SharePoint and Google Drive several times a day to a separate provider, for every client, as the baseline.
And it includes your cloud apps, which is the part almost nobody thinks about. Your accounting system, your CRM, your project tool, your e-commerce platform: each one holds data you couldn't rebuild, and each one's backup protects the vendor, not you. Many of them can be backed up outside the provider. QuickBooks Online, Salesforce, HubSpot, Shopify, Slack, Box, Dropbox, GitHub, Notion and Airtable all have export or backup routes, some through third-party backup services, some through their own APIs on a schedule. Others can only be exported by hand. The test for each app: if this vendor closed tomorrow, or an attacker deleted everything in it, what would we have? If the answer is "nothing," you need a copy the vendor doesn't control, even if it's a monthly export to that same isolated backup.
6. Rehearse the bad day. Once a year, sit the leadership team down for an hour and walk through it: an agent has your admin account, what happens in the next four hours? Then actually restore something from the backup. A backup nobody has restored from is a hope.
The uncomfortable version of the point
The labs will fix the test environments. Irregular will stop naming fake companies after real ones. Google, OpenAI and Anthropic will add guardrails, and I'll keep writing this column with the tool. None of that changes what the incidents proved: an AI agent with an internet connection and a target will find the guessable password and the leaked key, and it will do it faster than anyone on your side can react.
The companies that get through the next few years unbothered aren't the ones with the cleverest defenses. They're the ones where the password can't be guessed, the key was never leaked, someone is watching at machine speed, and when all of that fails anyway, there's a copy of everything the attacker never touched. One question to answer this week: if Microsoft, Google or your line-of-business app lost your data tomorrow, where is the other copy and who holds it? If you don't know, run our free external scan at secure.methodologyit.tech or book 15 minutes and we'll show you what an attacker can reach from outside, and what would survive if they got in.
Sources: Gizmodo, Sept 18, 2026 · TechCrunch, Aug 27, 2026: every time AI has gone rogue and hacked other companies · Axios, Sept 19, 2026 · Microsoft Services Agreement, §6
Ready to make IT work?
No pressure, no sales pitch. A senior tech will walk your environment with you and leave you with a report — whether you hire us or not.