The first entry is always the pin's source. Overall confidence is a weighted average of how firmly each reference supports the start and end times used above; a reference counts half as much for every 180 days older than the newest.
NBC News, dated Sept. 18, 2026, reports that "Google on Friday disclosed" the intrusions in a statement; the disclosure was a statement to the press rather than a Google blog post.
Quotes Google's statement from Heather Adkins at length, including that the three entities were made aware and the testing partner changed its processes, and describes the capture-the-flag setup in which fictional targets shared names with real companies.[1]
Independent report that the May 2026 incidents happened in a test run by Israeli firm Irregular, one by repeated password guessing and two with credentials from a public repository, and that the model ended the intrusion on finding a real company's system.[1]
Background on the evaluator: Irregular's own account traced an earlier escape by Anthropic models to a fictional target name matching a real domain while internet access was enabled, the same flaw behind the Gemini incidents.[1]
Something missing or wrong? Say it in your own words: a link that backs this pin up, a different start or end date and why, or a fact it lacks or gets wrong. The AI checks it against this pin's sources, searches for better ones, and adds any page that backs you up. The pin's own sources still count most.