183m passwords leaked: what Gmail users should do now

183m passwords leaked: what Gmail users should do now
183 million credential pairs uploaded to HIBP.
Editorial Team

Key points

  • 183 million credential pairs uploaded to HIBP.
  • Most entries stem from infostealer logs, not a Gmail breach.
  • Google says users remain protected but should take precautions.
  • About 8% of emails appear new to HIBP’s database.
By Editorial Team|Published 29-Oct-25|1 min read

A database containing 183 million email addresses and passwords has been added to the breach-tracking site Have I Been Pwned (HIBP), with confirmed credentials affecting users of Gmail, Outlook, Yahoo and other services. HIBP’s Troy Hunt said the trove comprises logs siphoned by information-stealing malware over recent years. While Google stressed there was no breach of Gmail itself and called reports of a service-level hack inaccurate, the cache raises risks for users who reuse passwords across sites. Preliminary analysis indicates about 92% of the credentials match data from previous exposures, while roughly 8%—an estimated 16.4 million addresses—appear new to HIBP. Google advised users to enable two-factor authentication, switch to unique passwords or passkeys, and immediately change any credentials that appear in breach checks. Security analysts also recommend using the HIBP lookup tool to see whether an email address is listed and to avoid password reuse that can enable credential-stuffing attacks.

Corrections & clarifications

Spot an inaccuracy or need more detail? Email connect@newsnexus24.com. Significant updates are timestamped above.

Story tags

Recent Stories

183m passwords leaked: what Gmail users should do now