{"id":6543,"date":"2025-08-30T10:06:02","date_gmt":"2025-08-30T10:06:02","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/08\/30\/google-warns-2-5b-gmail-users-to-reset-passwords-following-salesforce-data-breach\/"},"modified":"2025-08-30T10:06:02","modified_gmt":"2025-08-30T10:06:02","slug":"google-warns-2-5b-gmail-users-to-reset-passwords-following-salesforce-data-breach","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/08\/30\/google-warns-2-5b-gmail-users-to-reset-passwords-following-salesforce-data-breach\/","title":{"rendered":"Google Warns 2.5B Gmail Users to Reset Passwords Following Salesforce Data Breach"},"content":{"rendered":"<p>    Google Warns 2.5B Gmail Users to Reset Passwords Following Salesforce Data Breach<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Google has issued a broad security alert to its 2.5 billion Gmail users, advising them to enhance their account security in the wake of a data breach involving one of the company\u2019s third-party <a href=\"https:\/\/cybersecuritynews.com\/shinyhunters-breaches\/\" target=\"_blank\" rel=\"noreferrer noopener\">Salesforce systems<\/a>.<\/p>\n<p>The incident, which occurred in June 2025, has escalated concerns over sophisticated phishing campaigns targeting a massive user base.<\/p>\n<p>In June, a threat group identified as <a href=\"https:\/\/cybersecuritynews.com\/shinyhunters-breaches\/\" target=\"_blank\" rel=\"noreferrer noopener\">UNC6040<\/a>, also known by its extortion brand ShinyHunters, successfully infiltrated a corporate Salesforce instance used by Google. This system stored contact information and sales notes for small and medium-sized businesses.<\/p>\n<p>According to Google\u2019s analysis, the threat actor accessed and retrieved a limited set of data containing basic, largely public business information like company names and contact details.<\/p>\n<p>Google has emphasized that the breach did not compromise consumer products like Gmail or Google Drive and that no passwords or financial data were exposed.<\/p>\n<p>The attackers employed a <a href=\"https:\/\/cybersecuritynews.com\/social-engineering-tactics\/\" target=\"_blank\" rel=\"noreferrer noopener\">social engineering<\/a> tactic known as voice phishing, or \u201cvishing,\u201d to gain initial access. By impersonating IT support staff over the phone, they deceived an employee into granting them system privileges.<\/p>\n<p>This allowed the hackers to exfiltrate data before their access was discovered and terminated by Google\u2019s security teams. ShinyHunters is a well-known group linked to recent breaches at other major companies, including Adidas, Cisco, and LVMH.<\/p>\n<p>While the stolen data itself is considered low-risk, security experts warn that it can be weaponized to create highly convincing phishing and vishing attacks.<\/p>\n<p>Attackers are leveraging the news of the breach to craft scams that appear legitimate, tricking users into revealing their login credentials or two-factor authentication (2FA) codes. The threat group is known for escalating its tactics by leaking data or using it for extortion to pressure victims.<\/p>\n<p>In response to the incident, Google promptly contained the breach, conducted an impact analysis, and began mitigation efforts.<\/p>\n<p>On August 5, the company publicly detailed the event and the activities of UNC6040. By August 8, Google <a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/voice-phishing-data-extortion\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">confirmed<\/a> it had completed sending email notifications to all parties directly affected by the breach.<\/p>\n<p>Given the heightened risk of follow-on attacks, Google is urging all Gmail users to remain vigilant and take proactive security measures. The company strongly recommends updating passwords, enabling two-factor authentication, and being wary of unsolicited emails or calls requesting personal information.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 89%,rgb(169,184,195) 100%)\"><strong>Find this Story Interesting! Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get More Instant Updates<\/strong>.<\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/gmail-users-password-reset\/\">Google Warns 2.5B Gmail Users to Reset Passwords Following Salesforce Data Breach<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/gmail-users-password-reset\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Google Warns 2.5B Gmail Users to Reset Passwords Following Salesforce Data Breach Google has issued a broad security alert to its 2.5 billion Gmail users, advising them to enhance their account security in the wake of a data breach involving one of the company\u2019s third-party Salesforce systems. The incident, which occurred in June 2025, has [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1636,129,63],"tags":[130],"class_list":["post-6543","post","type-post","status-publish","format-standard","hentry","category-cyber-attack-news","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6543"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=6543"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6543\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=6543"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=6543"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=6543"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}