Google Confirms Gmail Was Not Breached After Reports of 183 Million Password Leak Google confirmed that Gmail was not breached after reports claimed 183 million Gmail passwords had leaked, stating the figure refers to credentials collected from infostealer malware and older data breaches, not a direct attack on Google's systems. The confusion arose after a routine update to the Have I Been Pwned breach notification service, which added the dataset. Google advised users to check their accounts via breach-checking tools, change passwords if needed, and enable two-factor authentication. Google Confirms Gmail Was Not Breached After Reports of 183 Million Password Leak Google https://www.ghacks.net/2026/08/06/google-sets-september-4-removal-date-for-google-assistant-on-mobile-as-gemini-takes-over/ says Gmail https://www.ghacks.net/2026/04/10/gmail-adds-end-to-end-encryption-for-android-and-iphone-users-in-google-workspace/ was not breached, despite reports claiming that 183 million Gmail passwords had leaked. According to the company, these reports are based on a misunderstanding. The 183 million number refers to a collection of credentials gathered from infostealer malware and older data breaches, not from a direct attack on Google's systems. The confusion started after a routine update to a third-party breach notification service. The credentials appeared in the Have I Been Pwned breach notification service, which led to the reports. What Actually Happened With the 183 Million Credentials The 183 million credentials come from infostealer logs and earlier data breaches collected over time, not from a Gmail breach. These datasets combine credentials stolen from many sources by malware that grabs saved passwords from infected devices. The data was added to Have I Been Pwned, which lets users check if their credentials have appeared in known breaches. Google says the reports misread this routine update as proof of a new Gmail attack. "Reports of a 'Gmail security breach impacting millions of users' are false. Gmail's defenses are strong, and users remain protected," Google said. The company clarified that infostealer databases collect credentials from a wide range of sources and are not indicative of a breach targeting Gmail specifically. Gmail was not breached, but infostealer malware can still collect valid Gmail passwords from infected devices. In these cases, the credentials come from users' own compromised machines or earlier unrelated breaches, not from Google's servers. The risk to each user depends on whether their credentials were included in an infostealer log, not on a breach of Gmail itself. What Gmail Users Should Do Now Even though Gmail was not breached, users should still check that their accounts are secure, since infostealer datasets may include valid credentials: - Check whether your email address appears in known breach datasets through a service like Have I Been Pwned. - Change your Gmail password if you suspect your credentials may have been exposed, and avoid reusing it across other services. - Enable two-factor authentication on your Google account, which protects the account even if the password is exposed. - Consider switching to a passkey for Google sign-in, which does not rely on a static password. - Run a reputable anti-malware scan if you suspect an infostealer infection, since these harvest saved passwords directly from the device. Google continues to say that Gmail's defenses are strong and that the breach reports are false. It is not clear how many of the 183 million credentials actually match active Gmail accounts, since the dataset comes from many sources over time. Users who are concerned should check their accounts with breach-checking tools instead of assuming they are either fully safe or affected by a Gmail-specific breach.