
Google has issued a worldwide security alert urging its 2.5 billion Gmail users to update their passwords after hackers breached a Salesforce database containing business contact information linked to the company. While no consumer Gmail or Cloud accounts were directly compromised, the breach has fueled a surge in phishing and impersonation attacks targeting users across the platform.
The incident, disclosed on August 5, involved the hacker group ShinyHunters, which gained access by impersonating an IT help desk to a Google employee and deploying malware to extract data. The stolen information included company and customer names used for Google’s advertising outreach. Although passwords and sensitive personal data were not exposed, Google warned that the information is being exploited to create highly convincing phishing emails and “vishing” phone scams.
Google said the attackers also compromised OAuth tokens for the Drift Email integration within Salesforce. As a precaution, the company revoked the affected tokens, notified impacted Google Workspace administrators, and temporarily disabled Gmail’s integration with Salesloft Drift. In a statement, Google stressed that there was “no compromise of Google Workspace or Alphabet itself.”
According to Google’s threat research team, phishing and voice-based scams now account for 37 percent of successful account takeovers across its platforms. To mitigate risks, the company is recommending several security measures, including updating passwords, enabling non-SMS two-factor authentication, and enrolling in its Advanced Protection Program. It also urged users to adopt passkeys, which rely on biometric authentication such as fingerprints or facial recognition, as a more secure alternative to traditional passwords.
Google has not provided a timeline for additional disclosures or technical updates related to the breach. Users seeking more guidance are being directed to the company’s official security help resources. In the meantime, Gmail users are being advised to stay vigilant by monitoring login alerts, enabling phishing filters, and avoiding suspicious links.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543