Warning to Gmail users as 183 MILLION passwords are stolen
Share and Follow

Gmail users are being urged to take immediate action following the alarming revelation that over 183 million passwords have been compromised in a recent data breach.

Australian cybersecurity expert Troy Hunt has brought this incident to light, indicating that the breach has exposed both email addresses and their corresponding passwords, putting countless accounts at risk.

Describing it as a ‘vast corpus’ of breached data, Hunt notes that the total size of this compromised information is a staggering 3.5 terabytes. To illustrate the magnitude, this data volume is comparable to storing 875 full-length HD movies.

Hunt also highlights that this breach affects all major email service providers, not just Gmail. This means that users of Outlook, Yahoo, and other popular services are also potentially vulnerable.

According to Mr Hunt, ‘all the major providers have email addresses in there’ – so not just Gmail, but Outlook, Yahoo and others too.

‘They’re from everywhere you could imagine, but Gmail always features heavily,’ Hunt told the Daily Mail. 

So have you been caught up in the incident?

Here’s how to check if your email data has been compromised. 

It's the email provider of choice for around 2 billion people worldwide. But Gmail has been involved in a huge data breach affecting more than 183 million user accounts

It’s the email provider of choice for around 2 billion people worldwide. But Gmail has been involved in a huge data breach affecting more than 183 million user accounts 

The incident occurred in April 2025 but has only just been disclosed on Mr Hunt’s Have I Been Pwned (HIBP) website

According to the expert, breached data contained 183 million unique email addresses alongside the websites they were entered into and the passwords used. 

To check if you’ve been compromised, head to the Have I Been Pwned website and enter your email address in the search bar. 

Next, tap on the button marked ‘Check’ and the site will show you the list of data breaches affecting your email address.

Even if not included in the new Gmail breach, your email address may have been involved in past breaches going back over a decade. 

If you are one of the 183 million people affected in this latest incident, you need to change your email password as soon as possible. 

Once this is done, enable two-factor authentication (2FA) if you haven’t already – which sends a code to your smartphone to get into your online accounts.

According to Mr Hunt, this incident is not a single breach but a collection of ‘stealer logs’ – a series of data files generated and compiled by ‘malware’ (malicious software).

To check if you've been compromised, head to the Have I Been Pwned website and enter your email address in the search bar

To check if you’ve been compromised, head to the Have I Been Pwned website and enter your email address in the search bar

How to check if you’re affected 

  1. Head to Have I Been Pwned
  2. Enter your email address in the search bar and tap ‘Check’ 
  3. Check the list of breaches involving your email address
  4. Change your password if it has been involved in a breach

‘Stealer logs are more of a firehose of data that’s just constantly spewing personal info all over the place,’ Mr Hunt explained in his blog post. 

‘Once the bad guys have your data, it often replicates over and over again via numerous channels and platforms.’ 

As yet, there’s no word on the identify of the criminals responsible for the malware, however. 

The expert stressed that it’s not just the password associated with your email account that has been potentially compromised. 

Also at risk are the unique passwords associated with your email address that you use on other websites too, such as Amazon, eBay and Netflix. 

He added: ‘Stealer logs expose the credentials you enter into websites you visit then login to.’ 

Therefore, if you find your email address under Have I Been Pwned it would be worth changing your password on any platform that uses it. 

Generally, people put themselves at greater risk by using the same single password across all their various online accounts. 

Graham Cluley, a computer expert and security blogger, said people should ‘always use different passwords’ for different online accounts.

‘You won’t be able to remember them by yourself, so use a password manager to do it for you,’ Mr Cluley told the Daily Mail. 

‘Always enable multi-factor authentication when available for a higher level of protection.

‘We’re not talking about one company getting hacked, but millions of people unknowingly having their passwords stolen through malware.

‘With 183 million email addresses exposed, it’s possible that many people could be caught up in this without even realising their computers have been compromised.’ 

Benjamin Brundage at cybersecurity platform Synthient, which ‘detects and blocks bad actors’, was the one that discovered the breached data and sent it to HIBP. 

Mr Brundage – who is in his final year of college in the US – advised users not to assume they are safe simply because they use strong passwords, which are considered the first line of defence against cyber incidents. 

A strong password is at least 16 characters long and includes a mix of capital and lowercase letters as well as numbers and symbols. 

What is Have I Been Pwned? 

Cybersecurity expert and Microsoft regional director Tory Hunt runs ‘Have I Been Pwned’.

The website lets you check whether your email has been compromised as part of any of the data breaches that have happened. 

If your email address pops up you should change your password. 

Pwned Passwords 

To check if your password may have been exposed in a previous data breach, go to the site’s homepage and enter your email address. 

The search tool will check it against the details of historical data breaches that made this information publicly visible. 

If your password does pop up, you’re likely at a greater risk of being exposed to hack attacks, fraud and other cybercrimes. 

Mr Hunt built the site to help people check whether or not the password they’d like to use was on a list of known breached passwords. 

The site does not store your password next to any personally identifiable data and every password is encrypted.

Other Safety Tips 

Hunt provides three easy-to-follow steps for better online security. 

First, he recommends using a password manager, such as 1Password, to create and save unique passwords for each service you use. 

Next, enable two-factor authentication. Lastly, keep abreast of any breaches.

Share and Follow
You May Also Like
FILE - The gates of Harvard Yard at Harvard University, Tuesday, Sept. 30, 2025, in Cambridge, Mass. (AP Photo/Charles Krupa, File)

Trump Administration Challenges Court Ruling on Harvard’s Federal Funding Reinstatement

The Trump administration is challenging a federal judge’s decision to overturn billions…
Alyssa Milano celebrates 53rd birthday with annual makeup-free selfie

Alyssa Milano Marks 53rd Birthday with Her Signature Makeup-Free Selfie

Isn’t she a vision? Actress Alyssa Milano delighted her Instagram followers this…
DOJ accused of censoring Epstein files as full documents are redacted

Controversy Erupts Over DOJ’s Heavily Redacted Epstein Documents

The Department of Justice is facing backlash after heavily redacting documents from…
'My dad is dead': Slain Jacksonville musician's family demands arrest in road rage shooting

Family of Slain Jacksonville Musician Urges Arrest in Fatal Road Rage Incident

The family of Joe Starkey, a beloved musician in Jacksonville, has expressed…
Investigation begins into plane crash that killed NASCAR driver Biffle and 6 others

Tragic Plane Crash Claims NASCAR Driver Biffle and Six Others as Investigation Commences

Authorities are delving into the mystery of who piloted the aircraft and…
Cancer added to list of line-of-duty benefits for firefighters

Firefighters Gain Vital Line-of-Duty Cancer Benefits: A Milestone in Health Protection

On Thursday, President Donald Trump signed a new act that expands benefits…
A poster seeking information about the campus shooting suspect is seen on the campus of Brown University, Wednesday, Dec. 17, 2025, in Providence, R.I. (AP Photo/Robert F. Bukaty)

Anonymous Hero: The Tip That Solved the Brown University Shooting Mystery

A crucial tip from a passerby led authorities to identify the suspect…
Policy group praises Trump’s 100 global wins since taking office, from cartel crackdowns to peace deals

Policy Group Highlights Trump’s 100 Global Achievements: From Combating Cartels to Securing Peace Deals

EXCLUSIVE: A fresh report from Polaris National Security, unveiled on Wednesday, outlines…