What does “Google data breach” really mean?
“Google data breach” is a phrase people typically search for when they want to know whether their Gmail address or Google account credentials were exposed in a data breach. So what is a Google data breach, exactly?
The phrase does not mean that Google’s servers were breached. Google’s Gmail encryption protects your messages as they travel and while they’re stored, and none of the incidents behind the recent headlines involved attackers breaking into Gmail or taking passwords stored by Google. Most were credential leaks in which Gmail addresses and passwords were either stolen from users’ own devices by infostealer malware (such as RedLine or Vidar) or exposed in data breaches at third-party platforms.
The phrase “Google data breach” turns up so often because Gmail is the world’s most widely used email service, with billions of users. So when people search for it, what they’re usually trying to find out is whether their credentials leaked — and the answer is that their credentials may well have leaked, just through some other door.
Recent data breaches and leaks that exposed Google credentials
Several incidents since 2025 have reached the news as possible Google Gmail data breaches and put Gmail users on alert. These incidents fall into two groups. The first is an attack on a third-party CRM system that Google used to store business contact information. The second is a series of large credential dumps compiled from logins that criminals collected over time.
Google Salesforce data breach (2025)
In mid-2025, the hacker group ShinyHunters compromised a Google Salesforce database through social engineering. Vishing was the group’s way in. Members posed as internal IT staff over the phone and convinced a Google employee to approve a tampered version of Salesforce Data Loader, which gave the attackers access to the database.
Google confirmed the incident in August 2025. According to the company, the stolen data was limited to basic and largely public business information, such as business names and contact details. No passwords were stolen. Media reports then claimed that Gmail users had been affected and that Google was warning them to change their passwords. On September 1, 2025, Google publicly denied issuing any broad Gmail data breach warning and called those claims “entirely false.”
For most people with a Gmail account, the risk from this incident is indirect. Stolen business contact details can make phishing calls and emails look more credible, so treat any unexpected message from “Google support” with caution.
Gmail credential dumps (2025–2026)
The two largest recent leaks of Gmail passwords were not caused by a breach of Google’s systems. Both were aggregated collections — years of stolen logins, most taken from people’s devices by infostealer malware, then lumped into one file and recirculated as a single dump.
In October 2025, security researcher Troy Hunt added a 3.5 TB dataset to Have I Been Pwned. The threat intelligence firm Synthient had compiled the data from criminal Telegram channels and forums. The dataset contained 183 million unique email accounts, each paired with the website it was used on and its password. Gmail addresses made up a large share of those accounts, but the dataset covered many email providers. About 16.4 million of the addresses had never appeared in a data leak before. Google publicly called reports of a Gmail data breach false.
Then, about three months later, in January 2026, cybersecurity researcher Jeremiah Fowler found an unprotected 96 GB database holding about 149 million logins. An estimated 48 million of them were Gmail accounts. The records included usernames, passwords, and direct links to the login pages where they were used. According to Fowler, the data most likely came from infostealer malware, and the database kept growing during his investigation. That suggests the malware feeding it was still active.
If your credentials ended up in one of these dumps, the risk is direct. A leaked Gmail password stays valid until you change it, and if you reused that password to create accounts on other sites, then those accounts are exposed as well. Attackers run stolen login details against other sites almost automatically — a tactic known as credential stuffing.
How to check if your Gmail was found in a data breach
If you suspect your Gmail credentials have leaked, the fastest way to find out is to run a data breach check. To check your email address, you can use Have I Been Pwned, a website that searches records of known breaches and credential dumps. To check your passwords, you can use Google Password Checkup, a tool built into your Google Account that scans your saved passwords against known leaks. Both tools are free and take only a few minutes to use.
Run a data breach check on your email
Have I Been Pwned is the simplest way to run a data breach check on your Gmail address. The check should take you no more than a minute:
- 1.Go to haveibeenpwned.com.
- 2.Type your Gmail address into the search field.
- 3.Press Enter to start the search.
- 4.Review the results.
If your address appears in the service’s records, Have I Been Pwned lists each breach or credential dump it was found in. Each entry shows the date and the types of data exposed, such as email addresses, passwords, and phone numbers. An entry labeled “stealer log” deserves the most attention. It means infostealer malware captured your login details directly from an infected device. To see which websites those logs recorded for your address, you’ll need to verify that you own the email address and open your personal dashboard on Have I Been Pwned.
A clean result is reassuring, but it’s not a guarantee that your credentials have never leaked. Have I Been Pwned can only check against breach data that has surfaced and made it into its records. You can also check a specific password through the Pwned Passwords page, or sign up for free email alerts so you’ll know if your address turns up in a future breach.
Google Password Checkup
Google Password Checkup is a free tool built into Google Password Manager. It scans the passwords saved in your Google Account and flags any that are compromised. A compromised password is one that has been published online in a known data breach, and Google recommends changing those first.
Password Checkup can only review passwords stored in Google Password Manager. If a password isn’t saved there, it won’t be included in the check. You can open the tool in Chrome or on the web.
In Chrome:
- 1.Select the three-dot menu in the top-right corner.
- 2.Select “Passwords and autofill.”
- 3.Select “Google Password Manager.”
- 4.Select “Checkup” on the left side of the page.
On the web:
- 1.Go to passwords.google.com.
- 2.Select “Go to Password Checkup.”
- 3.Select “Check passwords.”
- 4.Sign in to your Google Account again if prompted.
Password Checkup then sorts the results into three groups: compromised, reused, and weak. Each flagged entry links to the website where the password is used, so you can change it there directly.
PRO TIP
Prioritize changing any passwords flagged as compromised — they are already in circulation and in active use.
What to do if your Google credentials were leaked
If your Gmail address or password has been leaked, don’t sit on it — work through these steps as soon as you can. And if you’ve already been locked out, start with Google Account recovery instead.
- 1.Change your Google password immediately. A leaked password stays usable until you replace it, so change it as soon as you learn about the leak, even if you’re away from home. If that means using a café or airport network, connect to NordVPN before you sign in. You can’t always tell whether a public hotspot is legitimate, and on a shared network, a VPN protects you from hackers who try to monitor or tamper with your traffic.
- 2.Turn on two-factor authentication or set up a passkey. Two-factor authentication (2FA) adds a second checkpoint, such as a code from an authenticator app, so a stolen password alone can’t open your account. A passkey replaces the password with a sign-in tied to your device. You can set up both under “Security” in your Google Account.
- 3.Check your recovery email and phone number. One of the first things attackers do when they get into an account is change the recovery details, so that the next password reset notification goes to them. Confirm that both the recovery email address and phone number are yours, and remove any you don’t recognize.
- 4.Review and remove third-party app access. Apps you have connected to your Google Account may have access to your Google Drive files, not only your email. However you rate how secure Google Drive is on its own, each connected app is another way in. Remove any you don’t recognize or no longer use. Read another of our articles for instructions on how to disconnect third-party apps from your Google Account.
- 5.Check Gmail for suspicious forwarding rules and filters. A forwarding rule can keep your emails flowing to an attacker even after you’ve changed your password. In Gmail, open “Settings,” select “See all settings,” and review the “Forwarding and POP/IMAP” tab and the “Filters and Blocked Addresses” tab. Delete any rule you didn’t create.
- 6.Watch for follow-up attacks. Leaked credentials can lead to targeted phishing and, in some cases, identity theft. You may receive emails or calls that mention your leaked sensitive data to seem credible, or messages from “Google support” urging you to act fast. Google rarely, if ever, calls users about account problems, so treat any such call as a scam.
How to limit your exposure in future data breaches
Even the biggest data breaches start with a single company’s database, and every account you create leaves a copy of your email address. You don’t control how well those companies secure their databases, so you have no way to guarantee your address will never appear in a future leak. What you can do is reduce the blast radius. The habits below can keep one exposed credential from leading to your other accounts and give you a better chance of spotting a compromise early.
- Give every account its own password. If you reuse a password, criminals who find it in a leaked database can use it to sign in to your other accounts. That’s why you should always give each account a different password. A secure password manager such as NordPass can create strong passwords and store them for you.
- Give out your main Gmail address less often. Every service that stores your address keeps it in a database that could suffer a data breach. For newsletters, loyalty programs, and one-time sign-ups, use a secondary address or an email alias. Keep your main Gmail address for important accounts, such as online banking and government services.
- Delete accounts you no longer use. An old account on a website you no longer use still stores your email address and possibly a password you might have reused elsewhere. When you close an account, ask the service to delete your personal data as well. Once your details are gone from that company’s database, a future breach there can’t expose them.
- Keep infostealers off your devices. Infostealer malware is behind many of the largest credential dumps, and it usually arrives with pirated software or fake downloads. Download apps only from official sources and install system updates promptly. On Windows and macOS, you can use NordVPN’s next-generation antivirus (also called NGAV), a comprehensive digital threat protection tool that helps protect against scams, phishing, and malware as one system. When NGAV is on, NordVPN scans your downloads and quarantines malicious files before they can run.
- Sign in only through Google’s own pages. Phishing pages copy Google’s sign-in screen to collect passwords, and those passwords can end up in the same dumps as infostealer logs. So instead of following a sign-in link from an email or text message, type accounts.google.com into your browser or open the Gmail app directly.
- Monitor the dark web for your email address. NordVPN’s Dark Web Monitor scans the dark web for leaked credentials tied to your email address and alerts you when it finds a match. An alert is your signal to act. Change the affected password, then open “Security” in your Google Account and check “Recent security activity” and “Your devices” for sign-ins you don’t recognize.
Online security starts with a click.
Stay safe with the world’s leading VPN