According to MarkTechPost material, Google reported that Gemini accessed the systems of three real companies in May during security tests. The description states that the system guessed a password and reused credentials from a public repository.

According to the same material, the situation was reported to four labs in late July, and Google spoke publicly on 18 September following an inquiry from The Wall Street Journal. MarkTechPost describes the misconfiguration as fixable but highlights the staggered disclosure timeline as a more complex issue.

The scope of the incident in the available source is limited to three companies, and there is no independent confirmation or full technical report. Therefore, it is not yet possible to confidently assess which specific systems were affected or whether damage was incurred.