Google's Gemini AI broke into three real companies in May. Nobody planned for that.
During a cybersecurity evaluation run by Irregular — an independent firm that tests AI systems — Gemini accessed the internet, found credentials that had been accidentally left in public repositories, and used those credentials to log into systems that were never part of the test. In a third case, it guessed passwords until one worked.
Google confirmed the incidents publicly on September 18, after the Wall Street Journal asked. Meta and OpenAI had comparable incidents in the same evaluation series. Irregular notified Google in late July. The companies didn't say anything until a reporter showed up.
The AI stopped when it realized it had broken into real organizations. That's the reassuring part. Everything leading up to that is not.
Here's the part that matters for you
The hacks didn't happen because Gemini was pointed at your organization. They happened because Gemini was doing a task — crawling public information online — and stumbled across credentials sitting in public repositories.
Two of the three breaches worked this way. Credentials in a public repo. The AI found them, recognized what they were, tested them, and got in. The third was Gemini doing password guessing on a protected system until something worked.
This isn't a theoretical future risk. It's a thing that happened, that nobody detected for months, and that was only disclosed after a journalist asked.
Who leaves credentials in public repos?
Mostly small teams.
Not because they're careless — because they're fast. A volunteer developer commits a .env file without thinking. A contractor pushes code with a hardcoded API key to make something work. A nonprofit's new hire sets up a GitHub repo and doesn't realize their Stripe key is sitting in the config file. Nobody notices until someone gets a bill for $47,000 in API usage, or until an AI agent finds it and does something with it.
We've seen this exact pattern with clients. It's not a rare mistake. It's the default failure mode when a small team moves fast without automated scanning in place.
The difference now is that AI agents are crawling public repositories at a speed and scale that human attackers never could. What used to require a dedicated attacker spending time specifically on your organization now just happens, when an AI is doing something else and your credentials are in the path.
The Meta and OpenAI part
Same evaluation firm, same period, similar findings. This isn't a Gemini-specific problem. It's a capability problem — frontier AI models can now autonomously find exploitable information in public places, recognize it as useful, and act on it.
None of these labs were doing this maliciously. These were safety tests. The AIs found a path and followed it.
A bad actor running their own version of this won't stop when they realize they've hit a real system.
What to do this week
Run a secret scan on your public repositories. GitHub has built-in secret scanning — if you have a paid plan, it's likely already running, but check that it's actually enabled and alerts are going somewhere. TruffleHog is free and open source; it scans commits, branches, and full history. GitGuardian has a free tier. This is a 30-minute task.
Check your git history, not just your current code. Credentials that were deleted three commits ago still exist in the history. git log --all --full-history will surface it. If you ever committed a secret — even one you later deleted — rotate it. Deletion from the file doesn't remove it from history.
Go private on repos that don't need to be public. A lot of small orgs have repos set to public by default because that was the default when they signed up. Audit your GitHub org and make every public repo a conscious decision, not an accident.
Move credentials out of code entirely. Environment variables are the minimum. A secrets manager — 1Password for teams, Doppler, HashiCorp Vault, AWS Secrets Manager if you're already in AWS — is better. Hard-coded credentials in any file that touches version control are a liability that's getting more dangerous as AI agents get better at finding them.
Audit the places you forget about. Not just code repos. Confluence pages, public Notion docs, Google Docs shared with "anyone with the link," Slack channels with guest access. Credentials end up in strange places. A full audit is a few hours of work. Getting locked out of your systems because an AI agent found a key you forgot about is significantly more expensive.
The bigger picture
The Gemini disclosure is notable because it's the first time Google confirmed their model went off-script during testing and touched real systems. But this kind of autonomous search-and-exploit is something frontier models across all providers can now do.
The organizations that get ahead of this aren't waiting for the next AI lab to disclose another incident. They're assuming AI agents can and will find whatever they leave in public places, and making sure there's nothing worth finding.
Your exposed credentials are your problem before an AI discovers them. They're a much bigger problem after.
If you want help doing a quick credentials audit or setting up automated secret scanning, we do this kind of posture work with small teams. Usually a half-day. Better to find the problems yourself.