{"id":436751,"date":"2026-01-25T15:30:12","date_gmt":"2026-01-25T15:30:12","guid":{"rendered":"https:\/\/www.newsbeep.com\/au\/436751\/"},"modified":"2026-01-25T15:30:12","modified_gmt":"2026-01-25T15:30:12","slug":"48-million-gmail-usernames-and-passwords-leaked-online-again-3","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/au\/436751\/","title":{"rendered":"48 Million Gmail Usernames And Passwords Leaked Online Again"},"content":{"rendered":"<p><img decoding=\"async\" class=\" top-image\" src=\"https:\/\/www.newsbeep.com\/au\/wp-content\/uploads\/2026\/01\/1769192172_276_0x0.jpg\" alt=\"Gmail logo displayed on smartphone.\" data-height=\"1723\" data-width=\"2585\" fetchpriority=\"high\" style=\"position:absolute;top:0\"\/><\/p>\n<p>48 million Gmail login credentials exposed in massive leak.<\/p>\n<p>SOPA Images\/LightRocket via Getty Images<\/p>\n<p>Updated January 25 with even more analysis of the publicly exposed database, which included 48 million Gmail username and passwords, from cybersecurity and privacy experts as well as security researcher Jeremiah Fowler, responsible for discovering the massive leak, totalling 149 million login credentials across a multitude of online services and platforms. <\/p>\n<p>A highly respected veteran security researcher has confirmed that a database of 149 million compromised credentials, including those for an estimated 48 million Gmail accounts, has been leaked online. \u201cThe publicly exposed database was not password-protected or encrypted,\u201d Jeremiah Fowler said, adding that the database of unique logins and passwords totalled \u201ca massive 96 GB of raw credential data.\u201d Here\u2019s what we know so far, and what action you need to take.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-1\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/01\/22\/lastpass-issues-critical-warning-for-users---password-attacks-underway\/\" target=\"_blank\" aria-label=\"LastPass Issues Critical Warning For Users \u2014 Password Attacks Underway\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/01\/22\/lastpass-issues-critical-warning-for-users---password-attacks-underway\/\" rel=\"nofollow noopener\">ForbesLastPass Issues Critical Warning For Users \u2014 Password Attacks UnderwayBy Davey Winder<\/a>149 Million Login Credentials Exposed In Leak \u2014 Including An Estimated 48 Million Gmail Accounts<\/p>\n<p>It\u2019s not been the greatest start to a new year when it comes to password security. The LastPass password manager has <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/01\/22\/lastpass-issues-critical-warning-for-users---password-attacks-underway\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/01\/22\/lastpass-issues-critical-warning-for-users---password-attacks-underway\/\" target=\"_self\" aria-label=\"issued a warning\" rel=\"nofollow noopener\">issued a warning<\/a> for millions of users as attacks have been confirmed as underway, <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/01\/16\/12-billion-linkedin-users-put-on-alert-after-policy-violation-attacks\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/01\/16\/12-billion-linkedin-users-put-on-alert-after-policy-violation-attacks\/\" target=\"_self\" aria-label=\"LinkedIn users\" rel=\"nofollow noopener\">LinkedIn users<\/a> are alsoon alert as policy violation scammers target account passwords, and now comes the breaking news that a whopping great 149 million compromised credentials have been exposed online in an unprotected database.<\/p>\n<p>According to cybersecurity researcher Jeremiah Fowler, who uncovered the leaked database and has published <a class=\"color-link\" href=\"https:\/\/www.expressvpn.com\/blog\/149m-infostealer-data-exposed\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.expressvpn.com\/blog\/149m-infostealer-data-exposed\/\" aria-label=\"a report\">a report<\/a> sharing his findings, the database contained a total of 149,404,754 unique logins and password.<\/p>\n<p>It should be noted that this is not a new breach of the services involved, and most likely is a database made up of data from <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/10\/28\/gmail-passwords-confirmed-as-part-of-183-million-account-data-breach\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/10\/28\/gmail-passwords-confirmed-as-part-of-183-million-account-data-breach\/\" target=\"_self\" aria-label=\"past breaches and infostealer logs\" rel=\"nofollow noopener\">past breaches and infostealer logs<\/a>. Nonetheless, all Gmail users, along with those of any online service, as this database has made it clear that this is not just a Google account problem, should take the following action right now: ensure you are not reusing any passwords, switch to passkeys if possible and enable secure two-factor authentication to protect your account. Do not wait, check your accounts and take your login security seriously. <\/p>\n<p>\u201cI saw thousands of files that included emails, usernames, passwords, and the URL links to the login or authorization for the accounts,\u201d Fowler has confirmed, adding that the database illustrates that cybercriminals themselves are \u201cnot immune to data breaches.\u201d<\/p>\n<p>Fowler has estimated the number of accounts for major services that had their compromised credentials included in the leaked database, with the most, by a long chalk, seemingly belonging to Gmail users.<\/p>\n<p>Here are the totals provided by Fowler, in order of volume:<\/p>\n<p>Gmail &#8211; 48 millionFacebook &#8211; 17 millionInstagram &#8211; 6.5 millionYahoo &#8211; 4 millionNetflix &#8211; 3.4 millionOutlook &#8211; 1.5 million<\/p>\n<p>Although it\u2019s not known for sure that this was a database used by cybercriminals, that would seem the most likely reason for it to exist. There is a chance that it was assembled for \u201clegitimate research\u201d purposes, but the ridiculously lax security around access makes me think otherwise. What is certain, however, is that \u201cthe number of records increased from the time I discovered the database until it was restricted and no longer available,\u201d Fowler said, so this was not some long-abandoned project but rather a live and active one.<\/p>\n<p>The good news, therefore, is that the database is no longer available online, although it took more than a month for Fowler to get it taken down. \u201cThe database had no associated ownership information,\u201d Fowler has confirmed, \u201cso I reported it directly to the hosting provider via their online report abuse form. I received a reply several days later stating that they do not host the IP, and it is a subsidiary that operates independently while still using the parent organization&#8217;s name.\u201d That hosting provider would not disclose any additional information regarding who managed the database,\u201d Fowler added.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-3\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/12\/04\/has-your-gmail-password-been-hacked-check-now-heres-how\/\" target=\"_blank\" aria-label=\"Has Your Gmail Password Been Hacked? Check Now, Here\u2019s How\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/12\/04\/has-your-gmail-password-been-hacked-check-now-heres-how\/\" rel=\"nofollow noopener\">ForbesHas Your Gmail Password Been Hacked? Check Now, Here\u2019s HowBy Davey Winder<\/a>Cybersecurity And Privacy Experts Speak Out On Credentials Database Exposure Impacting Gmail And Other Platforms<\/p>\n<p>Matt Conlon, CEO of Cytidel, has called it a treasure trove for anyone with malicious intent. \u201cInfo stealers have seen a significant rise in prevalence over the past few years,\u201d Conlon said, \u201cand a data breach like this highlights just how widespread this issue is.\u201d<\/p>\n<p>Meanwhile, Boris Cipot, a senior security engineer at Black Duck, said that \u201cthere is no way to know how much damage or data leakage occurred before it was removed,\u201d adding that \u201cthe database also contained logins for government, banking, and streaming services, making it a highly valuable target for cybercriminals.\u201d<\/p>\n<p>\u201cFowler believes the data was collected by infostealing malware, also known as a <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/01\/20\/critical-hidden-email-hack-warning-issued-for-gmail-and-outlook-users\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/01\/20\/critical-hidden-email-hack-warning-issued-for-gmail-and-outlook-users\/\" target=\"_self\" aria-label=\"keylogger\" rel=\"nofollow noopener\">keylogger<\/a>, which infects user devices and records their inputs,\u201d Cipot said. \u201cBecause the database was still growing during his investigation, this strongly suggests the malware is still active.\u201d<\/p>\n<p>Mayur Upadhyaya, CEO at APIContext, told me that the exposed database is a \u201cstark reminder\u201d that credentials don\u2019t just get stolen, but they also get reused. \u201cAnd that\u2019s where the real risk lies,\u201d Upadhyaya said, \u201conce login and password pairs are exposed, even from criminal infrastructure, they become fuel for credential stuffing: automated attempts to reuse those same credentials across other applications and services.\u201d<\/p>\n<p>Consumer privacy advocates, such as Chris Hauk from Pixel Privacy, said that \u201cthe exposure of such a huge number of credentials poses a significant risk to users who are not aware of the breach and to what extent they are exposed.\u201d Although once again, I should state that this does not appear to be a new breach of anything, per se, rather a compilation of previously compromised credentials. \u201cWhile it may be too soon to have this information included in the <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/12\/04\/has-your-gmail-password-been-hacked-check-now-heres-how\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/12\/04\/has-your-gmail-password-been-hacked-check-now-heres-how\/\" target=\"_self\" aria-label=\"HaveIBeenPwned\" rel=\"nofollow noopener\">HaveIBeenPwned <\/a>website&#8217;s extensive database,\u201d Hauk said, \u201cI still strongly recommend that users visit the site and enter their email address to determine whether their information has been exposed in previous data breaches.\u201d<\/p>\n<p>Hauk also recommended that consumers make use of a password manager that can provide \u201cwarnings about password reuse or if a login has been exposed in a breach,\u201c in order to \u201cmake it easy to guard against password reuse, and to update passwords when they need to be changed.&#8221;<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-4\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/01\/07\/these-3-passwords-can-get-you-hacked-michael-football-and-superman\/\" target=\"_blank\" aria-label=\"These 3 Passwords Can Get You Hacked: Michael, Football And Superman\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/01\/07\/these-3-passwords-can-get-you-hacked-michael-football-and-superman\/\" rel=\"nofollow noopener\">ForbesThese 3 Passwords Can Get You Hacked: Michael, Football And SupermanBy Davey Winder<\/a>That So Many Gmail Logins Can Be Leaked Is Evidence That Credential Compromise Is Now A Background Condition Of The Internet<\/p>\n<p>The takeaway from this latest exposure of compromised login data is, Shane Barney, chief information security officer at Keeper Security, told me, is \u201cit is the byproduct of an ecosystem that continuously harvests credentials from endpoints and quietly accumulates access over time.\u201d The 149 million-record dataset matters less because of its size, Barney said, and more because of what it represents: \u201cCredential compromise is now a background condition of the internet.\u201d<\/p>\n<p>Mark McClain, CEO at SailPoint, meanwhile, warned that \u201chackers today don\u2019t need to break your system to get in \u2014 they can simply walk through the front door with legitimate credentials.\u201d Which is why it is so critical to take identity security more seriously than ever, and ensure that your organization is able to monitor, grant and manage access dynamically based upon policy and context. Anything less and the result will be seen in the next database leak to be uncovered, no doubt. \u201cEvery access decision is driven by who or what the identity is, the context of the data they touch, and the security signals surrounding them,\u201d McClain concluded.<\/p>\n<p>Taking the security basics seriously, and I mean really seriously, should also be on your agenda, whether corporate or consumer-oriented. Morey Haber, chief security advisor at BeyondTrust, recommended that my readers must always take note of the following: \u201cunique passwords for every site, never reusing passwords, enabling MFA or at least 2FA for website, using a monitoring service like LegalShield, LifeLock, etc. or even the built in password security detection built into Apple IOS to determine if credentials are exposed on the dark web so users can change their passwords \u2013 and lastly, never accepting 2FA\/MFA notifications unless you have initiated them.\u201d<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-5\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/01\/16\/facebook-password-warning-for-3-billion-users-as-attacks-surge\/\" target=\"_blank\" aria-label=\"New Facebook Warning For 3 Billion Users After Password Attacks\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2026\/01\/16\/facebook-password-warning-for-3-billion-users-as-attacks-surge\/\" rel=\"nofollow noopener\">ForbesNew Facebook Warning For 3 Billion Users After Password AttacksBy Davey Winder<\/a>Google Says It Will Force Password Resets When Exposed Gmail Credentials Are Identiifed<\/p>\n<p>I reached out to my contacts at Google and Gmail for a statement and a spokesperson told me: &#8220;We are aware of reports regarding a dataset containing a wide range of credentials, including some from Gmail. This data represents a compilation of &#8216;infostealer\u2019 logs\u2014credentials harvested from personal devices by third-party malware\u2014that have been aggregated over time. We continuously monitor for this type of external activity and have automated protections in place that lock accounts and force password resets when we identify exposed credentials.&#8221; <\/p>\n<p>So, to reiterate, this is not a new breach; it impacts multiple services, and is most likely a compilation of <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/10\/28\/gmail-passwords-confirmed-as-part-of-183-million-account-data-breach\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/10\/28\/gmail-passwords-confirmed-as-part-of-183-million-account-data-breach\/\" target=\"_self\" aria-label=\"existing compromised credentials\" rel=\"nofollow noopener\">existing compromised credentials<\/a>. Gmail just happens to be the one that is featured most, by some margin, within it. So don\u2019t panic, but do ensure you have unique passwords and ideally make use of the Google passkey function instead.<\/p>\n","protected":false},"excerpt":{"rendered":"48 million Gmail login credentials exposed in massive leak. SOPA Images\/LightRocket via Getty Images Updated January 25 with&hellip;\n","protected":false},"author":2,"featured_media":222909,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[64,63,226359,226358,226354,28708,226355,226353,226357,226356,90016,105],"class_list":["post-436751","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-au","tag-australia","tag-credentials-leaked","tag-expressvpn","tag-gmail-login","tag-gmail-password","tag-gmail-password-leak","tag-gmailleak","tag-has-gmail-been-hacked","tag-has-my-gmail-password-been-hacked","tag-password","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/436751","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/comments?post=436751"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/436751\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media\/222909"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media?parent=436751"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/categories?post=436751"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/tags?post=436751"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}