Massive Data Breach Leaves 183 Million Email Credentials, Including Gmail Passwords, Exposed: Report

The threat actors reportedly leveraged stealer logs containing the website address, email address, and passwords.

Advertisement
Written by Shaurya Tomer, Edited by Ketan Pratap | Updated: 28 October 2025 09:10 IST
Highlights
  • The breach included both email addresses and their associated passwords
  • Around 16.4 million accounts were reportedly leaked for the first time
  • You can check if your email was exposed on the Have I Been Pwned’ website

The datasets reportedly contained from about 3.5 billion records

Photo Credit: Reuters

Cybersecurity researchers have discovered a massive data breach involving tens of millions of leaked Gmail accounts. According to a report, the breach occurred in April of this year and was recently made public, with a record of over 183 million credentials in total. It not only includes email accounts, but also the passwords that are associated with them. The data breach is reportedly part of a larger stealer ecosystem, typically resulting from malware on the victim's machine.

Massive Data Breach Exposes Credentials

According to cybersecurity expert Troy Hunt, the massive volume of threat intelligence data was collated by Benjamin Brundage from the cybersecurity company Synthient. They managed to pull data from various sources, including criminal marketplaces, social media, forums, and Telegram, amounting to a total of 3.5TB.

Advertisement

The vast corpus contained several files, with the largest of them being 2.6TB in size and featuring a document with almost 23 billion rows. This puts the data breach among the largest ones in recent years, comparable with the mysterious database discovered in May this year that contained 16 billion records.

As per Hunt, the new dataset contained 183 million unique accounts. What's more concerning here is that 16.4 million of those had never been discovered in any data breach prior to this. While most of the data was reportedly sourced from recycled datasets, millions of Gmail accounts were verified, where exposed passwords were still in active use.

Advertisement

The threat actors reportedly leveraged stealer logs containing the website address, email address, and passwords. It involves infecting the victim's machine with malware and capturing credentials as they input them on a website.

Additionally, stuffing lists were also allegedly used, aggregated from other places where credentials are usually obtained, either stored in plain text files or protected with simple, crackable algorithms. As per the report, these lists are then used to access other accounts where the passwords have been reused.

Advertisement

Hunt said that credential stuffing lists are an extremely serious threat as they contain keys to numerous services. They reportedly serve as a gateway to takeovers of an immeasurable number of social media accounts, email addresses, and other personal resources, subsequently resulting in massive data breaches.

The leaked data was sent to the ‘Have I Been Pwned' website, and it is searchable. Users can run their email addresses on the website and check if their credentials have been exposed in any data breach.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. OpenAI Reportedly Eyeing AI Smartphones With Custom Chips
  2. Apple's Foldable iPhone Might Be Slightly Thicker Than This Model
  3. Xiaomi 17T Key Specifications Revealed Via Benchmarking Site
  4. XChat Debuts on iPhone: What is It, Key Features and How the App Works
  5. OnePlus Nord CE 6 Lite Price Range, Chipset and More Details Revealed
  6. Aave Urges Arbitrum to Release $73.5 Million ETH for rsETH Recovery
  1. Aave Labs Urges Arbitrum DAO to Release $73 Million in Frozen ETH for rsETH Recovery
  2. JBL Bar 1300MK2, 1000MK2, 800MK2, 500MK2 Soundbars Launched in India: Price, Features
  3. Apple’s Foldable iPhone Will Be Slightly Thicker Than iPhone 17 Pro Max, Leaked Schematics Show
  4. Dell XPS 14, Dell XPS 16 Refreshed With Up to Intel Core Ultra X7 358H CPU, Up to 16-Inch Displays: Price, Features
  5. OpenAI Developing Custom Chips With MediaTek, Qualcomm for ‘AI Agent’ Smartphones: Ming-Chi Kuo
  6. OnePlus Nord CE 6 Lite Price Range, Chipset and Other Key Specifications Revealed as India Launch Draws Near
  7. Bitcoin Trades Near $78,000 as ETF Inflows and Macro Optimism Support Stabilising Cryptocurrency Prices
  8. Assassin's Creed Hexe Game Director Exits Ubisoft Months After Creative Director Left Project
  9. OnePlus Confirms New 120W Dual-Port, 100W GaN Chargers Will Launch Alongside OnePlus Ace 6 Ultra
  10. Samsung Galaxy Book 6 Edge Price, Key Specifications Listed by Retailer Ahead of Launch
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.