Privacy News Google Confirms Gmail Was Not Breached After Reports of 183 Million Password Leak

Brownie2019

Level 23
Thread author
Verified
Well-known
Forum Veteran
Mar 9, 2019
1,071
5,902
2,168
Germany
Google says Gmail was not breached, despite reports claiming that 183 million Gmail passwords had leaked. According to the company, these reports are based on a misunderstanding.

The 183 million number refers to a collection of credentials gathered from infostealer malware and older data breaches, not from a direct attack on Google's systems. The confusion started after a routine update to a third-party breach notification service.

The credentials appeared in the Have I Been Pwned breach notification service, which led to the reports.

What Actually Happened With the 183 Million Credentials​

The 183 million credentials come from infostealer logs and earlier data breaches collected over time, not from a Gmail breach. These datasets combine credentials stolen from many sources by malware that grabs saved passwords from infected devices.

The data was added to Have I Been Pwned, which lets users check if their credentials have appeared in known breaches. Google says the reports misread this routine update as proof of a new Gmail attack.

"Reports of a 'Gmail security breach impacting millions of users' are false. Gmail's defenses are strong, and users remain protected," Google said. The company clarified that infostealer databases collect credentials from a wide range of sources and are not indicative of a breach targeting Gmail specifically.

Gmail was not breached, but infostealer malware can still collect valid Gmail passwords from infected devices. In these cases, the credentials come from users' own compromised machines or earlier unrelated breaches, not from Google's servers.

The risk to each user depends on whether their credentials were included in an infostealer log, not on a breach of Gmail itself.

What Gmail Users Should Do Now​

Even though Gmail was not breached, users should still check that their accounts are secure, since infostealer datasets may include valid credentials:

  1. Check whether your email address appears in known breach datasets through a service like Have I Been Pwned.
  2. Change your Gmail password if you suspect your credentials may have been exposed, and avoid reusing it across other services.
  3. Enable two-factor authentication on your Google account, which protects the account even if the password is exposed.
  4. Consider switching to a passkey for Google sign-in, which does not rely on a static password.
  5. Run a reputable anti-malware scan if you suspect an infostealer infection, since these harvest saved passwords directly from the device.
Google continues to say that Gmail's defenses are strong and that the breach reports are false. It is not clear how many of the 183 million credentials actually match active Gmail accounts, since the dataset comes from many sources over time.

Users who are concerned should check their accounts with breach-checking tools instead of assuming they are either fully safe or affected by a Gmail-specific breach.
 
Key distinction

The information describes a credential-compilation incident, not evidence that Google’s Gmail servers were breached. Infostealer logs can contain Gmail addresses and passwords taken from infected devices, browsers, password managers, or unrelated services. Their presence in a dataset does not establish when they were stolen or whether the credentials still work.

Have I Been Pwned can help identify whether an email address appears in known datasets, but it cannot determine whether a specific Gmail account is currently compromised or whether the password came from Google.

Concerned users should:

  • Review Google Account security activity and signed-in devices through the official Google Account website.
  • Change the password from a trusted, malware-free device, especially if it was reused elsewhere.
  • Enable two-step verification or a passkey.
  • Revoke unfamiliar sessions, applications, and third-party access.
  • Run a scan with reputable security software if an infostealer infection is possible.
  • Change other passwords that were stored in or entered on the potentially infected device.

A password change alone may not be sufficient if the device remains infected, because the new password could also be captured. The available description should therefore be treated as a warning about exposed credentials, not as proof of a Gmail-specific breach.