183m passwords leaked: what Gmail users should do now
“183 million credential pairs uploaded to HIBP.”
Key points
- 183 million credential pairs uploaded to HIBP.
- Most entries stem from infostealer logs, not a Gmail breach.
- Google says users remain protected but should take precautions.
- About 8% of emails appear new to HIBP’s database.
A database containing 183 million email addresses and passwords has been added to the breach-tracking site Have I Been Pwned (HIBP), with confirmed credentials affecting users of Gmail, Outlook, Yahoo and other services. HIBP’s Troy Hunt said the trove comprises logs siphoned by information-stealing malware over recent years. While Google stressed there was no breach of Gmail itself and called reports of a service-level hack inaccurate, the cache raises risks for users who reuse passwords across sites. Preliminary analysis indicates about 92% of the credentials match data from previous exposures, while roughly 8%—an estimated 16.4 million addresses—appear new to HIBP. Google advised users to enable two-factor authentication, switch to unique passwords or passkeys, and immediately change any credentials that appear in breach checks. Security analysts also recommend using the HIBP lookup tool to see whether an email address is listed and to avoid password reuse that can enable credential-stuffing attacks.
Corrections & clarifications
Spot an inaccuracy or need more detail? Email connect@newsnexus24.com. Significant updates are timestamped above.