In early 2026, a cybersecurity researcher discovered an unsecured database containing 149,404,754 stolen credentials—including roughly 48 million Gmail addresses and their passwords. Here’s what happened, what wasn’t a Gmail breach, and what you should do right now to find out if your account is at risk.

Total Accounts Exposed: 183 million · Gmail Credentials Leaked: 48 million · Database Size Reported: 149 million usernames and passwords · Recent Breach Dates: Jan–Mar 2026 · Check Tool: Have I Been Pwned

Quick snapshot

1Confirmed facts
2What’s unclear
  • Exact overlap between 2025 and 2026 exposed accounts
  • Whether all 48 million Gmail addresses represent unique users
  • How long the database was publicly accessible before discovery
3Timeline signal
  • 2014: ~5 million Gmail accounts dumped on Russian forum (Security.org historical breach data)
  • Oct 2025: 183M dataset added to Have I Been Pwned (Security.org HIBP timeline)
  • Jan 2026: Fowler discovers 96 GB unsecured database (Security.org 2026 discovery report)
4What’s next
  • Check your email at Have I Been Pwned
  • Change any exposed passwords immediately
  • Enable two-factor authentication on critical accounts

Two major incidents dominate the recent Gmail password landscape: the October 2025 Have I Been Pwned upload and the January 2026 unsecured database discovery.

Metric Value Source
Largest leak (total accounts) 183 million unique emails Security.org
Gmail credentials in 2026 database 48 million Security.org
Total records in Fowler database 149,404,754 records Fox News
Fowler database file size 96 GB Fox News
Genuinely new credentials (2025) 16.4 million Security.org
Facebook accounts in same database 17 million Fox News
Instagram accounts 6.5 million Fox News
HIBP tracks pwned websites 917 Have I Been Pwned

Have Gmail passwords been leaked?

In October 2025, Troy Hunt added a 183 million unique email/password dataset to Have I Been Pwned (HIBP), compiled by threat intelligence firm Synthient. The dataset totaled 3.5 terabytes, though 91% of the credentials had been seen in prior breaches, leaving 16.4 million genuinely new accounts. In late January 2026, cybersecurity researcher Jeremiah Fowler separately discovered an unsecured 96 GB database containing 149,404,754 stolen credentials—approximately 48 million of them Gmail addresses.

Recent leaks involving Gmail credentials

The 2026 database included credentials harvested by infostealer malware like RedLine and Vidar from infected devices, not stolen directly from Google’s servers. The database was publicly accessible with no password, access controls, or encryption for weeks before Fowler’s discovery. Other platforms in that database: 17 million Facebook accounts, 6.5 million Instagram, 4 million Yahoo Mail, 3.4 million Netflix, 1.5 million Outlook, and 420,000 Binance credentials. Google has denied any breach of its own infrastructure in both the 2025 and 2026 incidents.

To be clear, the credentials in this dataset were not stolen from Google’s servers. They were harvested by infostealer malware.

— Security.org (security news publication)

Reported sizes: 48M and 183M accounts

Some media incorrectly reported the October 2025 HIBP upload as a direct “Gmail breach,” but it was actually a compilation of infostealer data from multiple services including Apple, Facebook, Snapchat, and Gmail. Email accounts dominated the 2026 database, raising risks for account recovery across services since many platforms use email as the primary identity anchor.

Why this matters

Password reuse is one of the primary risks enabling credential stuffing attacks. Even if your Gmail password wasn’t “stolen from Google,” it can still be exposed if you used the same password elsewhere and that service was breached.

Password reuse is a primary risk, enabling credential stuffing without direct Gmail hacks. The 2025 dataset was inaccurately reported as a “Gmail breach” by some outlets, though it was an infostealer credential compilation aggregated by Synthient and uploaded to HIBP by Troy Hunt, who maintains the breach-notification platform. The 2026 database included plaintext passwords, login URLs, and forensic signs of RedLine and Vidar malware. A 2014 credential dump on a Russian forum had previously exposed approximately 5 million Gmail accounts.

Should I be worried if my password is in a data leak?

Being included in a credential dump does not automatically mean your account has been accessed, but it dramatically increases your risk profile.

Impact of credential stuffing

Credential stuffing attacks automate login attempts across dozens of services using lists of stolen username/password pairs. Even if only 1% of reused passwords succeed against a popular service, the sheer volume of available credentials makes this attack class profitable for threat actors. The 2026 database was structured by victim and source, making it particularly useful for targeted credential stuffing campaigns.

The pattern: automated attacks thrive on password reuse, making every leaked credential a potential skeleton key across services.

Risks to Gmail users

Gmail accounts are especially valuable because they serve as account recovery anchors for nearly every other online service. A compromised Gmail account can lead to cascading takeovers of banking, social media, and work accounts. The 2026 Fowler database included 900,000 iCloud Mail, 780,000 TikTok, and 1.4 million .edu email credentials alongside Gmail, compounding the risk for users who reuse passwords across these platforms.

The catch: a Gmail compromise often triggers a chain reaction across banking, social media, and workplace accounts that rely on email for recovery.

A massive database containing 149 million stolen logins and passwords was found publicly exposed online.

— Fox News Tech (Fox News Tech)

The upshot

If your Gmail password appeared in either the 2025 HIBP dataset or the 2026 Fowler database, treat it as compromised immediately—not because your Gmail was hacked directly, but because the same password on any other service is now a live entry point for attackers.

What To Do When Your Password is Leaked in a Data Breach

If you discover your credentials in a breach database, act quickly on three fronts: change the compromised password, check for unauthorized activity, and prevent future reuse.

Immediate steps for compromised passwords

  • Change the password for the affected service first, then any other accounts using that same password
  • Use Google’s password manager at passwords.google.com to audit all stored credentials
  • Generate a new, unique password at least 16 characters with mixed character types
  • If you cannot remember which services share a password, reset them all starting with high-value accounts (banking, email, work)

Google Account recovery

If you suspect your Google Account has already been accessed without authorization, use the Google Account recovery page to verify recent activity and regain control. After recovery, immediately enable two-factor authentication. Google offers security keys and Google Authenticator as 2FA options; security keys are the strongest defense against phishing because they cannot be phished the way SMS codes or TOTP codes can.

Watch out

Phishing emails spike after major breach disclosures. Attackers send messages claiming to be from Google or your bank asking you to “verify your password.” Google will never ask for your password via email or links—navigate directly to myaccount.google.com for any account actions.

Can I tell if my Gmail has been hacked?

Several indicators suggest unauthorized access to your Google Account beyond the obvious sign of changed settings.

Signs of Google Account compromise

  • Unexpected security alerts from Google about login from unfamiliar location or device
  • Sent messages in your Gmail that you did not write, especially to contacts you rarely contact
  • Recovery email or phone number changed without your knowledge
  • Forwarding rules created in Gmail settings that auto-redirect messages to unknown addresses
  • Profile name or signature altered

Forbes 4 signs of email compromise

Reviews of security reporting identify four consistent warning signs: login activity from unfamiliar cities or countries, device sign-ins you don’t recognize, changes to account recovery options, and emails automatically archived or deleted to hide evidence. Google offers a dedicated security checkup page that lists all devices currently signed into your account and their last-known activity timestamps.

The trade-off

Many users discover their account was accessed long after the fact because attackers are silent—they use your storage and bandwidth rather than your visible settings. Regularly reviewing your Google account’s recent activity page is the only way to catch quiet intrusions.

How do I tell if my passwords are compromised?

The most reliable way to check whether your email or passwords have appeared in any data breach is to query breach-notification databases directly.

Use leak checkers

Have I Been Pwned (HIBP), maintained by Troy Hunt, aggregates breach data from thousands of incidents and allows free lookup by email address or password. Enter your Gmail address at haveibeenpwned.com to see which breaches contained your information. For passwords specifically, the Pwned Passwords tool lets you check whether a specific password has been seen in any known dump without exposing the password itself. Chrome also flags saved passwords that appear in known breaches via its password alert feature.

  • Visit haveibeenpwned.com and enter your Gmail address
  • Review each listed breach for details on what data was exposed
  • Use the Pwned Passwords search (haveibeenpwned.com/Passwords) to check specific passwords
  • Enable Chrome’s “Check saved passwords” feature in browser settings

Google password change tools

Google’s password manager at passwords.google.com shows all credentials stored in your Google Account, flags weak or reused passwords, and identifies passwords that have appeared in data breaches. You can use these tools to systematically audit and update every credential. Google Support also provides step-by-step guidance for changing compromised passwords in Google Account settings.

The implication: proactive checking through HIBP and Google’s tools gives you visibility into exposures before attackers exploit them.

Password reuse is one of the number one problems that cause massive breaches.

— Security analyst (YouTube breach analysis)

Bottom line: The Gmail credential leaks were infostealer compilations, not breaches of Google’s servers—but that distinction matters little if your password is now public. Check Have I Been Pwned now. If your Gmail password appears, change it everywhere you used it. Enable two-factor authentication on your Google Account and any other high-value service. Use a password manager to generate unique credentials for every account so that no single leak puts all your accounts at risk.

Breach Timeline

The timeline shows how credential compilation incidents have accelerated in scale and visibility over the past decade.

Date Event Source
2014 Credential dump on Russian forum exposing approximately 5 million Gmail accounts Security.org
October 2025 Synthient dataset (183 million unique emails) added to Have I Been Pwned by Troy Hunt; 3.5 TB with 91% previously known credentials Security.org
2025 Reports of 16 billion record aggregations surfaced, including Gmail credentials from prior leaks DeXpose
Late January 2026 Jeremiah Fowler discovers 96 GB unsecured database with 149,404,754 stolen credentials, including 48 million Gmail accounts Security.org / Fox News
March 31, 2026 Security.org publishes detailed analysis of Gmail breach incidents and user protection guidance Security.org

The implication: credential compilation incidents are accelerating in scale and visibility, but they remain fundamentally infostealer harvests rather than direct service breaches—a distinction that changes the remediation path for affected users.

What Experts Say

To be clear, the credentials in this dataset were not stolen from Google’s servers. They were harvested by infostealer malware.

— Security.org (security news publication)

A massive database containing 149 million stolen logins and passwords was found publicly exposed online.

— Fox News Tech (Fox News Tech)

Password reuse is one of the number one problems that cause massive breaches.

— Security analyst (YouTube breach analysis)

What this means: the threat is credential reuse at scale, not a flaw in Google’s own infrastructure. Users who treat every breach notification as a prompt to audit and diversify their passwords will reduce their exposure regardless of how the credentials were harvested.

Confirmed vs. Unconfirmed

Confirmed

  • Gmail appeared in 48 million credentials in the 2026 Fowler database
  • 183 million unique emails in the January 2026 HIBP upload
  • 16.4 million genuinely new credentials in the 2025 HIBP dataset
  • Credentials were harvested by infostealer malware, not stolen from Google servers
  • Google denied direct breach of its own infrastructure
  • Have I Been Pwned tracks 917 pwned websites as of latest data

Unclear

  • Exact overlap between 2025 and 2026 exposed Gmail accounts
  • Precise Gmail count within the 2025 HIBP dataset specifically
  • Precise discovery date when Fowler first found the unsecured database
  • Regional impact breakdown for affected users
  • Exact malware family distribution in the 2026 dataset

For users, the distinction between confirmed and unclear matters less than the action it demands: treat any exposed password as compromised, regardless of source.

Steps to Secure Your Gmail Right Now

Whether or not you find your credentials in a breach database, these steps reduce your exposure to credential-based attacks.

  1. Check Have I Been Pwned: Visit haveibeenpwned.com and enter your Gmail address. If it appears in any breach, change that password immediately.
  2. Change the exposed password: Navigate directly to myaccount.google.com → Security → Password Manager → change the password for your Gmail and any other account using the same password.
  3. Enable two-factor authentication: Go to myaccount.google.com → Security → 2-Step Verification. Choose a security key for the strongest protection or Google Authenticator for mobile convenience.
  4. Audit saved passwords: Use Chrome’s password manager or Google’s password manager to identify and update any weak, reused, or breached passwords.
  5. Review account activity: Check myaccount.google.com → Security → Manage all devices for any unfamiliar sessions. Sign out all devices and change your password if you see unknowns.
  6. Set up account recovery options: Verify your recovery phone number and email are current and not recently changed, so you can regain access if locked out.

Taking these steps now means attackers find a locked door rather than an open one, even if your credentials appeared in a future leak.

Why is Google warning Gmail users to stop using passwords?

Google has been pushing users away from passwords toward passkeys because passwords are inherently guessable, reusable, and phishable—while passkeys are bound to your device and cannot be intercepted in transit.

Shift to passkeys

Google’s password alert system flags when saved passwords appear in known breach dumps, triggering popup warnings that prompt users to change exposed credentials. This automated detection works alongside Google’s broader effort to eliminate password dependence through passkey adoption, which removes the need to remember or transmit passwords altogether.

Breach-related alerts

After incidents like the 2026 Fowler database discovery, Google may surface warnings in Gmail and Google Account interfaces when your credentials match exposed data. These alerts are designed to drive immediate action rather than waiting for users to discover compromises on their own.

Security upgrade path

Moving to passkeys eliminates the entire class of attacks that exploit stolen passwords. If your Google Account supports passkey login, enabling it removes the threat of credential stuffing against your Gmail, regardless of how many password dumps surface.

Related reading: Royal Bank of Canada Login Guide · Espace Client Hydro Quebec Login Guide

Amid claims of 48 million exposed Gmail credentials, facts, myths and protection steps from security experts help users distinguish alarm from actionable advice.

Frequently asked questions

What is the Have I Been Pwned service?

Have I Been Pwned (HIBP) is a breach-notification website maintained by security researcher Troy Hunt. It aggregates data from thousands of known breaches and allows users to search by email address or password to see whether their credentials have appeared in any documented leak. The service tracks 917 pwned websites as of the latest update.

How do I change compromised passwords in Google?

Navigate to myaccount.google.com, select Security from the left menu, click Password Manager, then choose the account you want to update. Google will prompt you to enter your current password and create a new one. Choose a password you have not used elsewhere and ensure it is at least 16 characters with a mix of uppercase, lowercase, numbers, and symbols.

What are signs your phone is hacked via email?

If attackers gain access through a compromised email password, you may notice unexpected SMS codes for 2FA attempts, contacts receiving spam from your address, unfamiliar apps installed on your phone, or your location settings showing activity you did not authorize. These signs suggest your Gmail account was the entry point for a broader device compromise.

Why avoid common passwords like those in leaks?

Credential dumps from infostealer malware include millions of real passwords that people actually use. Attackers build dictionaries from these leaks to speed up credential stuffing attacks. Any password found in a known breach dump—regardless of the account—was already tried by attackers at scale and should be considered burned.

Is Gmail the most hacked email?

Gmail is among the most targeted because its ubiquity makes it valuable as an account-recovery anchor. In the January 2026 Fowler database, Gmail credentials numbered approximately 48 million—more than Facebook’s 17 million—making it the single largest email provider represented. However, the scale reflects Gmail’s market dominance rather than a specific vulnerability in Google’s systems.

What caused the 48 million Gmail leak?

The 48 million Gmail credentials in the 2026 database came from infostealer malware that harvested passwords from infected user devices, not from a breach of Google’s servers. Google has denied any compromise of its own infrastructure. The database was a compilation assembled from thousands of individual infections, structured by victim and source, then left publicly accessible without encryption or access controls.

For anyone whose Gmail password appears in either of these major dumps, the path forward is clear: change the password today, enable two-factor authentication, and stop reusing passwords across services. Your inbox is the key to almost everything else you own online—treat it accordingly.