cd /news/artificial-intelligence/google-confirms-gmail-was-not-breach… · home topics artificial-intelligence article
[ARTICLE · art-98647] src=ghacks.net ↗ pub= topic=artificial-intelligence verified=true sentiment=· neutral

Google Confirms Gmail Was Not Breached After Reports of 183 Million Password Leak

Google confirmed that Gmail was not breached after reports claimed 183 million Gmail passwords had leaked, stating the figure refers to credentials collected from infostealer malware and older data breaches, not a direct attack on Google's systems. The confusion arose after a routine update to the Have I Been Pwned breach notification service, which added the dataset. Google advised users to check their accounts via breach-checking tools, change passwords if needed, and enable two-factor authentication.

read2 min views1 publishedAug 16, 2026
Google Confirms Gmail Was Not Breached After Reports of 183 Million Password Leak
Image: Ghacks (auto-discovered)

Google says Gmail was not breached, despite reports claiming that 183 million Gmail passwords had leaked. According to the company, these reports are based on a misunderstanding.

The 183 million number refers to a collection of credentials gathered from infostealer malware and older data breaches, not from a direct attack on Google's systems. The confusion started after a routine update to a third-party breach notification service.

The credentials appeared in the Have I Been Pwned breach notification service, which led to the reports.

What Actually Happened With the 183 Million Credentials #

The 183 million credentials come from infostealer logs and earlier data breaches collected over time, not from a Gmail breach. These datasets combine credentials stolen from many sources by malware that grabs saved passwords from infected devices.

The data was added to Have I Been Pwned, which lets users check if their credentials have appeared in known breaches. Google says the reports misread this routine update as proof of a new Gmail attack.

"Reports of a 'Gmail security breach impacting millions of users' are false. Gmail's defenses are strong, and users remain protected," Google said. The company clarified that infostealer databases collect credentials from a wide range of sources and are not indicative of a breach targeting Gmail specifically.

Gmail was not breached, but infostealer malware can still collect valid Gmail passwords from infected devices. In these cases, the credentials come from users' own compromised machines or earlier unrelated breaches, not from Google's servers.

The risk to each user depends on whether their credentials were included in an infostealer log, not on a breach of Gmail itself.

What Gmail Users Should Do Now #

Even though Gmail was not breached, users should still check that their accounts are secure, since infostealer datasets may include valid credentials:

  • Check whether your email address appears in known breach datasets through a service like Have I Been Pwned.
  • Change your Gmail password if you suspect your credentials may have been exposed, and avoid reusing it across other services.
  • Enable two-factor authentication on your Google account, which protects the account even if the password is exposed.
  • Consider switching to a passkey for Google sign-in, which does not rely on a static password.
  • Run a reputable anti-malware scan if you suspect an infostealer infection, since these harvest saved passwords directly from the device.

Google continues to say that Gmail's defenses are strong and that the breach reports are false. It is not clear how many of the 183 million credentials actually match active Gmail accounts, since the dataset comes from many sources over time.

Users who are concerned should check their accounts with breach-checking tools instead of assuming they are either fully safe or affected by a Gmail-specific breach.

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @google 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/google-confirms-gmai…] indexed:0 read:2min 2026-08-16 ·