US tech giant Google has issued a global security alert, advising its 2.5 billion Gmail users to update their passwords following a data breach involving one of its Salesforce databases.
While users' Gmail and Cloud accounts were not directly compromised, the incident sparked a wave of phishing and impersonation attacks targeting users across the platform.
While the exposed database did not contain passwords or sensitive user data, the stolen business contact information was used in a series of phishing campaigns that masqueraded as legitimate communications from Google.
According to Google's threat research team, phone scams and "vishing" — voice phishing — now account for 37% of successful account takeovers on Google platforms.
The breach involved business contact information such as company and customer names, which hackers used to create highly convincing phishing emails and voice-based social engineering scams.
The attackers behind the breach, identified as ShinyHunters, gained entry by impersonating a Google employee's IT support department, then deployed malware to exfiltrate database contents, according to a blog post from the tech giant on Aug. 5, 2025.
The breach, made public the same day, originated from a Salesforce database used internally by Google to manage potential advertisers.
The company said “only a small amount of basic business contact information used to communicate with potential advertisers” was exposed, not personal Gmail account login information.
Google said the breach was limited to Salesforce. According to Google, on August 28, 2025, the company's investigation confirmed that the attacker also compromised the OAuth tokens for the "Drift Email" integration.
In response to these findings and to protect customers, Google has identified affected users, revoked specific OAuth tokens issued to the Drift Email app, and disabled integration functionality between Google Workspace and Salesloft Drift pending further investigation.
This means that Google has temporarily suspended the connection between Gmail and Salesforce services to prevent any potential further breach./.
Source: https://www.vietnamplus.vn/google-canh-bao-25-ty-nguoi-tren-toan-cau-co-the-bi-xam-pham-du-lieu-gmail-post1059146.vnp
Comment (0)