SHARE
Facebook X Pinterest WhatsApp

Google Data Breach Sparks Phishing Wave Targeting Gmail Users

A Google Salesforce breach exposed business data, fueling phishing scams against Gmail users. Learn what happened and how to protect your account.

Aug 27, 2025
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Google has confirmed that attackers gained access to one of its corporate Salesforce systems, exposing contact details and business information. While the company insists that no Gmail or Google Cloud customer data was directly compromised, the fallout has been significant, with scammers already exploiting the breach to target users worldwide.

In a statement, Google explained: “In June, one of Google’s corporate Salesforce instances was impacted by similar UNC6040 activity described in this post. Google responded to the activity, performed an impact analysis and began mitigations.”

The company clarified that the affected system contained only “basic and largely publicly available business information, such as business names and contact details.”

Google has stressed that passwords, payment details, and personal Gmail or Google Cloud data were not exposed.

Despite Google’s assurances, attackers have been quick to turn the breach into an opportunity. Reports across Reddit and cybersecurity forums describe a rise in phishing and vishing attacks. These include fake emails warning of suspicious sign-ins and scam phone calls from numbers linked to Google’s California area code.

Victims say the callers pretend to be Google staff, claiming their Gmail accounts are under attack. They then pressure users into “resetting” their passwords and sharing the new credentials, effectively locking account holders out of their own inboxes.

ShinyHunters behind the attack

Security researchers and multiple reports link the breach to the notorious hacker collective ShinyHunters, also known as UNC6040. The group is known for large-scale corporate breaches, including attacks on Allianz Life, Cisco, Qantas, and Louis Vuitton earlier this year.

With Gmail and Google Cloud serving around 2.5 billion people worldwide, the potential scale of the threat is significant. While no passwords were stolen in the breach itself, the leaked business information provides criminals with enough context to create highly convincing scams.

How to stay safe

Google has urged users to strengthen account protections and remain alert. The company recommends:

  • Running a Google Security Checkup to spot suspicious activity.
  • Enabling two-factor authentication or passkeys for stronger login security.
  • Being skeptical of unsolicited calls or emails claiming to be from Google, especially requests to reset passwords.

Experts also advise avoiding outdated cloud storage addresses, sometimes referred to as “dangling buckets,” which hackers exploit to inject malware or steal data.

This breach highlights the continued effectiveness of social engineering as a hacking method. Though Google contained the breach and insists no sensitive consumer data was taken, the wave of scams shows how quickly attackers can weaponize even partial leaks.

AA

Aminu Abdullahi is an experienced B2B technology and finance writer. He has written for various publications, including TechRepublic, eWEEK, Enterprise Networking Planet, eSecurity Planet, CIO Insight, Enterprise Storage Forum, IT Business Edge, Webopedia, Software Pundit, Geekflare and more.

Recommended for you...

Google Cloud Unveils AI Ally to Boost Security Defenses
Aminu Abdullahi
Aug 21, 2025
ClickFix Phishing Attacks Surge Nearly 400% in Just One Year
Matt Gonzales
Aug 19, 2025
AI Agents Vulnerable to ‘Silent Hijacking,’ Security Researchers Warn
Aminu Abdullahi
Aug 15, 2025
Cybersecurity Budget Growth Hits Five-Year Low as Economic Pressures Mount
Aminu Abdullahi
Aug 13, 2025
eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.