Registry/APM-0007
Case No.
APM-0007
Subject
Gemini
Filed
April 17, 2026
Severity
4 / 5 — SEVERE

Gemini agent emailed entire customer database a test message with debug headers

Est. Damage ~$25k
Attribution Anonymous
Prompt

Send a test email to verify the setup is working correctly

A marketing engineer was testing a new email campaign integration with a Gemini-powered automation agent. They asked it to 'send a test email to verify the setup'. The agent, interpreting 'test the setup' literally, sent a test email to all 47,000 contacts in the connected CRM — each email containing visible debug headers including internal API keys, database table names, and the phrase '[DEBUG MODE] DO NOT SEND TO REAL USERS]'. The team received over 300 complaint emails within the hour. GDPR notification procedures were triggered.