logo
Confirmed: Google Has Been Hacked — User Data Compromised

Confirmed: Google Has Been Hacked — User Data Compromised

Forbes2 days ago
Update, August 8, 2025: This story, originally published on August 7, has been updated with additional information from cybersecurity experts regarding the confirmed hacking of Google that has exposed user data.
The Google Threat Intelligence Group has officially confirmed that user data has been stolen following a successful hack attack impacting one of its databases. Here's what we know so far.
Google Has Been Hacked — Data Has Been Compromised
This is not a warning that the Google Chrome web browser is in need of an urgent security update, or a story about switching from passwords to passkeys to protect your Google account. No, this is exactly what the headline says: Google has been hacked.
Source? That would be Google itself.
An August 5 posting by the Google Threat Intelligence Group has confirmed that one of the corporate databases was impacted by hackers thought to be associated with the ShinyHunters ransomware group, more formally known as UNC6040.
'Google responded to the activity, performed an impact analysis and began mitigations,' the GTIG posting stated, adding the database in question was a Salesforce instance 'used to store contact information and related notes for small and medium businesses.'
'The speed at which organisations are falling victim to cyber attacks targeting Salesforce instances is nothing short of alarming,' Robin Brattel, CEO at Lab 1, said. 'We need to be honest: malicious campaigns are being scaled quicker than ever as hackers are using information that's already been made public, often from past data breaches, to target organisations.'
Customer data was, Google said, 'retrieved by the threat actor,' in the short period of time that the attack window remained open. Although Google has not gone into great detail regarding the attack as of yet, it did confirm that the stolen data consisted of 'basic and largely publicly available business information, such as business names and contact details.'
I reached out to Google for a statement and a spokesperson told me that the 'details that we're able to share at this time can all be found in our blog update,' adding that this includes additional information regarding the ShinyHunters associated UNC6040 threat group, which 'provides the security community with actionable intelligence on this actor.'
Google also stated that ShinyHunters commonly uses an attack tactic of extorting victims using emails or telephone calls demanding bitcoin ransom payments within 72 hours of compromise. It has not, however, confirmed or denied that this was the case here. Google did confirm that the attack itself occurred in June.
What Cybersecurity Experts Have To Say About The Hacking of Google
'The news that Google has suffered a data breach in the recent wave of attacks executed by ShinyHunters highlights that no organisation is immune to cybercrime,' William Wright, CEO of Closed Door Security, said, adding: 'It doesn't matter if you are a small business or one of the world's leading technology firms, all organizations are vulnerable.' While Google's update provides an overview of how these attacks unfolded, Wright continued, 'it does not state whether the impacted organisations have been informed, or, if they have been informed, when they were informed.' Which means that the cybercriminals involved, ShinyHunters or not, could have had this information fro two months to do with what they saw fit.
'Google has long been one of the leading companies in the world when it comes to cybersecurity,' Jamie Akhtar, CEO of CyberSmart, said, concluding that 'if it can happen to one of the wealthiest and best-defended companies in the world, it can happen to anyone.'
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

5 secrets for breaking through the entry-level job ‘glass floor'
5 secrets for breaking through the entry-level job ‘glass floor'

Fast Company

time14 minutes ago

  • Fast Company

5 secrets for breaking through the entry-level job ‘glass floor'

From on-again-off-again tariffs, economic uncertainty, and layoffs, fresh graduates are in one of the toughest job markets in recent history. More than half do not have a job lined up by the time they graduate, and the unemployment rate for young degree holders is the highest it's been in 12 years, not counting the pandemic. Technological advancements are further making the situation harder, as artificial intelligence (AI) has wormed its way into the workforce, cannibalizing the number of entry-level jobs available. What's a young grad to do? I interviewed hiring managers, career advisers, and college students, and in this piece you'll learn: What out-of-work new grads need to be doing right now in their 'limbo' How to identify industries that are hiring you may never have thought of The right approach to developing AI literacy to stand out 1. Use limbo productively What several recent college grads refer to as 'limbo,' the time period between graduation and employment, is often regarded as an excruciating phase of uncertainty. Experts recommend using this time as an opportunity for gaining experience outside of traditional corporate work.

Microsoft Sued For Killing Windows 10—All Users Must Act Now
Microsoft Sued For Killing Windows 10—All Users Must Act Now

Forbes

time15 minutes ago

  • Forbes

Microsoft Sued For Killing Windows 10—All Users Must Act Now

Microsoft knows 'many millions of users will not buy new devices or pay for extended support' when Windows 10 goes end of life in October, a new lawsuit alleges. 'These users,' it claims, 'will be at a heightened risk of a cyberattack or other data security incident, a reality of which Microsoft is well aware.' The lawsuit filed in California by Lawrence Klein, the owner of two Windows 10 laptops set to become obsolete in 8 weeks, 'seeks injunctive relief requiring Microsoft to continue providing support for Windows 10 without additional fees or conditions until the number of devices running the operating system falls below a reasonable threshold.' Around 45% of all Windows users are still on the soon to be obsolete version of the OS and must now act to ensure PCs are safe from attack. That number was dropping, albeit it has seen a reverse following Microsoft's decision to offer varying support extensions. That means 700 million users will be affected come October 14. Klein says Microsoft decided to kill the older OS when 'Windows 10 users represented more than half of the Windows operating system (OS) market share.' He also references the 240 million PCs that cannot upgrade, 'forcing' users to 'buy new devices capable of running Windows 11 or pay unanticipated sums for extended support.' Putting upgrade costs aside, the security risks are clear. Microsoft's 'long-term business strategy' Klein says, 'will have the effect of jeopardizing data security not only of Microsoft's customers but also of persons who may not use Microsoft's products at all.' Windows 10 users can now extend support by paying between $30 and $60 or by for free subject to certain parameters. That support extension is available to all Windows 10 users, whether or not their PCs meet the hardware requirements for Windows 11. Arguably, a better solution would be to extend Windows 10 support for free for PCs that can't upgrade, while mandating the upgrade for those that can. This lawsuit is the latest twist in a the windy road Windows 10 users have followed for the last year. Klein claims Microsoft's primary intent in killing Windows 10 is ' to force its customers to purchase new devices optimized to run Microsoft's suite of generative AI software such as Copilot, which comes bundled with Windows 11 by default.' This approach, Klein's lawsuit says, has the 'inevitable effect of decreasing trade in generative AI products of Microsoft's competitors, increasing the barriers to entry in the generative AI market, and dampening innovation and consumer choice.' Klein wants Windows 10 to be supported until less than 10% of the Windows user base is using that version of the OS. That means more than 600 million more PCs upgrading to Windows 11. That will take some considerable time. I have approached Microsoft for any response to the lawsuit.

Man pushed onto train tracks at Midtown subway station in New York City, police say
Man pushed onto train tracks at Midtown subway station in New York City, police say

Fox News

time37 minutes ago

  • Fox News

Man pushed onto train tracks at Midtown subway station in New York City, police say

A man in New York City was pushed onto the train tracks at a Midtown subway station Saturday night, although he was not struck by a train, according to police. The victim, 44, was standing on the train platform of the 1 train at the 50th Street and 7th Avenue station shortly before 7:50 p.m. when someone pushed him from behind onto the tracks, a spokesperson for the New York City Police Department told Fox News Digital. The man was able to climb back onto the platform and did not make any contact with a train, police said. The victim suffered injuries to his face and legs and was transported by EMS to a hospital in stable condition. Police said the suspect fled the scene after pushing the victim onto the tracks. No arrests have been made, as police continue searching for the suspect. The incident remains under investigation. The push at the subway station comes after three people were shot during an early morning shooting in Times Square. A 17-year-old suspect was detained after that incident near the intersection of 44th Street and 7th Avenue at around 1:20 a.m. on Saturday. An 18-year-old woman and two men aged 19 and 65 were wounded in the shooting.

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store