Google says Gmail data secure despite leak

Google confirmed Gmail was not breached after reports claimed 183 million passwords had leaked. The tech giant called the reports a misunderstanding, explaining the credentials came from infostealer malware and older data breaches rather than a direct attack on its systems.
How the confusion started
The 183 million figure appeared in Have I Been Pwned, a service tracking compromised credentials. A routine database update triggered headlines suggesting a fresh Gmail breach. Google responded by stating the data was collected from multiple sources over time, not a single incident.
“Reports of a ‘Gmail security breach impacting millions of users’ are false,” Google stated. “Gmail’s defenses remain strong, and users are protected.”
Related: Perplexity Offers 34 Billion for Chrome Browser
The credentials originated from malware that steals saved passwords from infected devices. These logs often combine valid and outdated passwords, leaving uncertainty about how many of the 183 million were still active or linked to Gmail accounts.
The real risk to users
While Gmail itself wasn’t compromised, the malware poses a serious threat. If a device is infected, the software can harvest credentials stored in browsers or password managers. These stolen passwords may later appear in datasets like the one added to Have I Been Pwned.
Google explained the risk depends on individual habits. Some credentials in the dataset could be years old or tied to abandoned accounts. Others might still work, particularly if users haven’t updated passwords since the original breach.
This isn’t the first time aggregated breach data has caused confusion. In 2021, a collection of 3.2 billion credentials was mistakenly framed as a single massive leak. Such incidents reveal a recurring issue: third-party breach databases can spark alarm when updated, even if the data isn’t new.
Related: WhatsApp adds new group chat tools
What users should do now
Google suggested steps to secure accounts:
- Check if your email appears in known breach datasets using Have I Been Pwned or similar tools.
- Change your Gmail password if you suspect exposure, and avoid reusing it elsewhere.
- Enable two-factor authentication (2FA) on your Google account for added protection.
- Consider using a passkey, which removes the need for a static password.
- Run an anti-malware scan if you suspect your device might be infected.
The company stressed its systems remain secure. The situation shows a broader problem: how breach data is collected often differs from how it’s reported. For users, the main lesson is to focus on security habits rather than assuming a single breach—or its absence—tells the whole story.
Google did not estimate how many of the credentials were still valid or tied to active Gmail accounts. The dataset’s age and mixed origins make it hard to gauge the immediate risk.
