Google Data Breach Exposed 2.5 Billion Accounts: How to Secure Your Gmail Account

Google has reportedly advised Gmail users to update their passwords and strengthen their security.

Advertisement
Written by Akash Dutta, Edited by David Delima | Updated: 2 September 2025 12:31 IST
Highlights
  • Password hackers have reportedly breached 2.5 billion Gmail accounts
  • Google has reportedly notified impacted users via email
  • The threat actor has also targeted Salesforce database via OAuth tokens

Gmail users should secure their accounts by enabling two-factor authentication (2FA)

Photo Credit: Unsplash/Solen Feyissa

Google has reportedly alerted 2.5 billion Gmail account holders after a password hacker group was able to carry out a “successful intrusion.” As per the report, the incident occurred between August 8 and 18 in a widespread attack via compromised Open Authorisation (OAuth) tokens. Apart from targeting individual accounts, the threat actors have also targeted Salesforce's database containing information about its customers, the Google Threat Intelligence Group (GTIG) has found. The company has advised Gmail users to update their passwords and secure their accounts.

Update: Google has reached out to Gadgets 360 highlighting reports around the data breach were incorrect. The company stated in a blog post, "We want to reassure our users that Gmail's protections are strong and effective. Several inaccurate claims surfaced recently that incorrectly stated that we issued a broad warning to all Gmail users about a major Gmail security issue. This is entirely false."

You can read the full story here.

Threat Actor Target Gmail Account Passwords

The Mountain View-based tech giant reportedly alerted impacted Gmail users via email, asking them to update their passwords immediately and increase the security of their accounts by activating two-factor authentication (2FA). Additionally, the company is said to have advised users to remain alert for suspicious activity.

Advertisement

The same hacker group, tracked as UNC6395, was found to be involved in a widespread data theft campaign targeting Salesforce customer data, GTIG said in a blog post. This occurred as a result of compromised OAuth tokens “associated with the Salesloft Drift third-party application.”

Advertisement

As a protective measure, Salesloft has revoked all active access and refresh tokens that came from the Drift application. Salesforce has also removed Drift from its AppExchange until further investigation is conducted.

While the enterprise-focused attack was mitigated via a combined effort by GTIG, Salesforce, and Salesloft, individual Gmail account holders need to take proactive steps to secure their accounts to protect themselves from any potential data breaches. Google suggests a series of steps a user can take to ensure the security of their accounts.

How to Secure Your Gmail Account

  1. Run Google's Security check-up by navigating to your Google account, then Settings > Security > Security check-up. Fix any red or amber items.
     
  2. Update your password by going to Security > Password > *Set a new password. Google recommends using a unique and strong alphanumeric password which includes capitalisation and special characters.
     
  3. Turn on 2FA by navigating to Security > 2-Step Verification, and adding a passkey. You can also opt to use an authenticator app to receive OTPs to verify your identity.
     
  4. Review devices and active sessions by visiting Security > Your devices. Sign out of anything you do not recognise or no longer use.
     
  5. Revoke third-party access and app passwords by navigating to Security > Third-party access, and removing any apps that you do not need or trust.
     
  6. Monitor your recent login activity by opening the Gmail web page, then tapping on *Details located at the bottom right corner.
     
  7. Never click on a URL or attached file sent from an email address you do not recognise. Even if it is a familiar account, always verify with the sender via a separate platform.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Google, Gmail, Data Privacy, 2FA, Cybersecurity
Advertisement

Related Stories

Popular Mobile Brands
  1. Poco X8 Pro, Poco X8 Pro Max to Launch on This Date
  2. SanDisk Extreme Fit USB Type-C Flash Drive Launched in India at This Price
  3. Samsung Galaxy M17e 5G India Launch Set for March 17: Features
  4. Vivo V70 FE Arrives With a 7,000mAh Battery: See Price, Specifications
  5. Vivo X300s Expected to Launch Soon as Company Executive Reveals Key Features
  6. OnePlus 15T Official Images Confirm 'Squircle' Camera, Two Colourways
  7. Poco C85x 5G Key Features Revealed a Day Ahead of Launch in India
  1. NASA’s Webb Telescope Confirms Asteroid 2024 YR4 Will Safely Pass the Moon in 2032
  2. ChatGPT Adult Mode Delayed Again as OpenAI's 'Code Red' Reportedly Ends
  3. Lava Bold 2 5G India Launch Date Announced; Confirmed to Feature Under-Display Fingerprint Scanner
  4. Realme Note 80 Launched With 6,300mAh Battery, 6.74-Inch Display: Price, Specifications
  5. Anthropic’s Claude Finds 22 Vulnerabilities in Mozilla Firefox in Just Two Weeks
  6. Samsung Galaxy Smartphones Get Inactivity Restart Security Feature With Latest Update: Report
  7. Poco C85x 5G Key Specifications, Features Revealed a Day Ahead of Launch in India
  8. Rooster Now Available for Streaming Online: What You Need to Know About its Plot, Cast, and More
  9. Bhartha Mahasayulaku Wignyapthi OTT Release Date Reportedly Revealed: When and Where to Watch Ravi Teja’s Romantic Drama Online?
  10. Ghost Elephants Out on OTT: Know Where to Watch This Biographical Film Online
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.