Google Alerts 2.5B Gmail Users After Salesforce Database Breach and Phishing Attack

Students walk on an outdoor part of a university campus.

Google has alerted its 2.5 billion Gmail users following a targeted phishing and vishing attack that compromised a corporate Salesforce database containing business contact information. The incident follows a similar breach at TransUnion that exposed 4.4 million Americans’ data through Salesforce-connected systems. The security incident did not involve any Gmail password breaches, but rather focused on business contact details stored in Google’s corporate systems.

The attack sequence began with a vishing (voice phishing) phone scam targeting a Google employee, which resulted in brief unauthorized access to the company’s Salesforce database. Vishing attacks have become increasingly sophisticated, with attacks increasing 442 percent in 2024 due to AI-enhanced social engineering tactics. Attackers subsequently used the stolen contact information to launch sophisticated phishing campaigns, attempting to deceive users into revealing their credentials and two-factor authentication (2FA) codes through fake Google sign-in pages.

In response, Google has implemented enhanced security measures and urged users to strengthen their account protection through several recommended steps that typically require about five minutes to complete. The measures include reviewing account activity, enabling stronger authentication methods, and maintaining vigilance against phishing attempts. The security updates support Google’s recent initiative to mandate multi-factor authentication for all cloud services by 2025.

Gmail’s current security infrastructure includes multiple warning systems that alert users to potential threats, such as suspicious login attempts from new devices or locations, phishing attempts, suspicious attachments, unusual account activity, and sender verification failures related to email authentication protocols including SPF, DKIM, and DMARC. The protocols have become increasingly important as sophisticated phishing campaigns continue to evolve.

For enterprise customers, Google has expanded its security offerings to include end-to-end encryption (E2EE) capabilities, enabling fully encrypted email transmission across the open internet, even to non-Gmail recipients. The client-side encryption feature, which prevents Google from accessing message contents, is available to Google Workspace Enterprise Plus customers with the Assured Controls add-on.

Google recommends that organizations implement comprehensive security measures beyond Gmail’s built-in protections, including firewalls, Zero Trust policies, and Endpoint Detection & Response (EDR) solutions. The recommendation comes as the Zero Trust Security market is projected to reach $60.7 billion in the coming years. For individual users, the company emphasizes the importance of verifying the authenticity of Google sign-in pages, enabling strong two-factor authentication, regularly monitoring account activity, and maintaining updated software and browsers.

Sources: Passionate Penny Pincher, OpenEDR, Cyber Insider