Google Data Breach Exposed 2.5 Billion Accounts: How to Secure Your Gmail Account

Google has reportedly advised Gmail users to update their passwords and strengthen their security.

Advertisement
Written by Akash Dutta, Edited by David Delima | Updated: 2 September 2025 12:31 IST
Highlights
  • Password hackers have reportedly breached 2.5 billion Gmail accounts
  • Google has reportedly notified impacted users via email
  • The threat actor has also targeted Salesforce database via OAuth tokens

Gmail users should secure their accounts by enabling two-factor authentication (2FA)

Photo Credit: Unsplash/Solen Feyissa

Google has reportedly alerted 2.5 billion Gmail account holders after a password hacker group was able to carry out a “successful intrusion.” As per the report, the incident occurred between August 8 and 18 in a widespread attack via compromised Open Authorisation (OAuth) tokens. Apart from targeting individual accounts, the threat actors have also targeted Salesforce's database containing information about its customers, the Google Threat Intelligence Group (GTIG) has found. The company has advised Gmail users to update their passwords and secure their accounts.

Update: Google has reached out to Gadgets 360 highlighting reports around the data breach were incorrect. The company stated in a blog post, "We want to reassure our users that Gmail's protections are strong and effective. Several inaccurate claims surfaced recently that incorrectly stated that we issued a broad warning to all Gmail users about a major Gmail security issue. This is entirely false."

You can read the full story here.

Threat Actor Target Gmail Account Passwords

The Mountain View-based tech giant reportedly alerted impacted Gmail users via email, asking them to update their passwords immediately and increase the security of their accounts by activating two-factor authentication (2FA). Additionally, the company is said to have advised users to remain alert for suspicious activity.

Advertisement

The same hacker group, tracked as UNC6395, was found to be involved in a widespread data theft campaign targeting Salesforce customer data, GTIG said in a blog post. This occurred as a result of compromised OAuth tokens “associated with the Salesloft Drift third-party application.”

Advertisement

As a protective measure, Salesloft has revoked all active access and refresh tokens that came from the Drift application. Salesforce has also removed Drift from its AppExchange until further investigation is conducted.

While the enterprise-focused attack was mitigated via a combined effort by GTIG, Salesforce, and Salesloft, individual Gmail account holders need to take proactive steps to secure their accounts to protect themselves from any potential data breaches. Google suggests a series of steps a user can take to ensure the security of their accounts.

How to Secure Your Gmail Account

  1. Run Google's Security check-up by navigating to your Google account, then Settings > Security > Security check-up. Fix any red or amber items.
     
  2. Update your password by going to Security > Password > *Set a new password. Google recommends using a unique and strong alphanumeric password which includes capitalisation and special characters.
     
  3. Turn on 2FA by navigating to Security > 2-Step Verification, and adding a passkey. You can also opt to use an authenticator app to receive OTPs to verify your identity.
     
  4. Review devices and active sessions by visiting Security > Your devices. Sign out of anything you do not recognise or no longer use.
     
  5. Revoke third-party access and app passwords by navigating to Security > Third-party access, and removing any apps that you do not need or trust.
     
  6. Monitor your recent login activity by opening the Gmail web page, then tapping on *Details located at the bottom right corner.
     
  7. Never click on a URL or attached file sent from an email address you do not recognise. Even if it is a familiar account, always verify with the sender via a separate platform.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Google, Gmail, Data Privacy, 2FA, Cybersecurity
Advertisement

Related Stories

Popular Mobile Brands
  1. Starlink Will Offer Unlimited Satellite Internet in India at This Price
  2. OnePlus Pad Go 2 First Impressions
  3. Battlefield 6's Next Season 1 Update Arrives This Week: All You Need to Know
  4. 'High' Risk Vulnerabilities Discovered in Google Chrome and Edge Browsers
  5. OnePlus 15R Roundup: Price in India, Specs and Everything We Know So Far
  6. OnePlus Pad Go 2 Key Features Revealed: Here's When It Goes on Sale in India
  1. Scientists Unveil Screen That Produces Touchable 3D Images Using Light-Activated Pixels
  2. SpaceX Expands Starlink Network With 29-Satellite Falcon 9 Launch
  3. Nancy Grace Roman Space Telescope Fully Assembled, Launch Planned for 2026–2027
  4. Hell’s Paradise Season 2 OTT Release Date: When and Where to Watch it Online?
  5. Francis Lawrence’s The Long Walk (2025) Now Available for Rent on Prime Video and Apple TV
  6. Nicolas Cage Starrer Spider-Noir Set to Release on Prime Video in 2026
  7. Devi Chowdhurani OTT Release Date: When and Where to Watch Srabanti Chatterjee’s Period Drama Online?
  8. OnePlus Pad Go 2 Key Specifications and Sale Date Revealed; Will Feature Dimensity 7300-Ultra SoC
  9. OpenAI Claims Increased Enterprise Usage Amid CEO’s Code Red Declaration
  10. Samsung's One UI 8.5 Beta Update Rolls Out to Galaxy S25 Series in Multiple Regions
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.