Google is facing one of the most serious security breaches in its history, after hackers exposed sensitive data that could impact more than 2.5 billion Gmail users worldwide. The attack, carried out by the notorious hacking group ShinyHunters, has left users vulnerable to phishing scams, fake calls, and malicious text messages.
The breach, which took place in June 2025, stemmed from a clever social engineering scheme. Cybercriminals impersonated IT officials over the phone and tricked a Google employee into approving a malicious Salesforce application. That single mistake opened the door for attackers to extract business contact details, names, and notes from Google’s Salesforce database.
Although Google confirmed that no direct login credentials were stolen, the exposed data is already being used in targeted phishing campaigns. Users are reporting a surge in fraudulent emails and calls attempting to trick them into revealing sensitive information.
A Familiar Pattern for Google
This isn’t the first time Google has faced large-scale security threats. Past incidents include the 2018 Google+ API breach, the 2017–2018 Gmail phishing wave, and the 2016 Gooligan malware campaign. Each case has highlighted how attackers don’t always need passwords to cause serious damage.
Hackers often rely on impersonation techniques, brute force logins with weak passwords, and targeted scams. For victims, the risks are severe: being locked out of Gmail accounts, losing personal documents and photos, or even exposing linked financial and corporate systems.
Google’s Response
Google began investigating immediately and formally notified impacted users on August 8, 2025. The company emphasized that most of the exposed data was limited to basic, publicly available business information.
Here’s what Google said in its official statement:
“In June, one of Google’s corporate Salesforce instances was impacted by similar UNC6040 activity described in this post. Google responded to the activity, performed an impact analysis and began mitigations. The instance was used to store contact information and related notes for small and medium businesses. Analysis revealed that data was retrieved by the threat actor during a small window of time before the access was cut off. The data retrieved by the threat actor was confined to basic and largely publicly available business information, such as business names and contact details.”
While Google downplayed the severity, cybersecurity experts warned that even basic details can be enough for hackers to launch convincing phishing attacks at scale.
Who Are the ShinyHunters?
The breach has been linked to ShinyHunters, also known as UNC6040, a hacking group infamous for high-profile attacks on companies like AT&T, Microsoft, Santander, and Ticketmaster.
Founded in 2020, the group’s playbook is straightforward but effective: impersonate IT support, trick employees into granting app permissions, and then use Salesforce-style Data Loader tools to siphon off massive datasets.
What You Can Do to Stay Safe
While the breach may feel overwhelming, there are steps Gmail users can take right now to reduce their risk:
- Reset your Gmail password immediately, especially if you’ve reused it elsewhere.
- Enable two-factor authentication (2FA) for phishing-resistant logins.
- Check if your account data is on the dark web using tools like ID Protection’s Data Leak Checker and Dark Web Monitoring.
- Use Trend Micro ScamCheck or similar services to block scam calls, filter phishing SMS, and flag suspicious activity.
The Bigger Picture
The Gmail breach highlights how social engineering, not technical flaws, often becomes the weakest link in cybersecurity. Even the most advanced tech companies can be compromised when human error enters the equation.
For billions of Gmail users, the lesson is clear: stay vigilant, strengthen account security, and never assume a company as large as Google is immune to breaches.
Schema Selected:
