Data breach
Google (Partial)
- Records
- 2,550,800
- Breach date
- 10 October 2025Estimated
- Added
- 3 October 2025
What was exposed
3 types of data
- Email addresses1
- Home addresses1
- Phone numbers1
About this breach
Attackers gained access to a Google corporate Salesforce database by tricking an employee over the phone, and a cybercrime group claims the theft involved roughly 2.55 million records tied to prospective Google Ads customers. Google has confirmed the breach and notified affected businesses. According to our investigation team, the listing contains 2,550,800 rows and was added to our index on October 3, 2025, with an estimated attack date of October 10, 2025. External reporting, including coverage by BleepingComputer, traces the initial intrusion to June 2025.
The attackers, a group Google's threat intelligence team tracks as UNC6040 and known publicly as ShinyHunters, posed as IT support during a voice phishing call and persuaded a Google employee to install a modified version of Salesforce's Data Loader tool. That tool was then used to pull data out of a single Salesforce instance Google uses to communicate with potential advertising customers. ShinyHunters later told BleepingComputer it demanded 20 Bitcoins, roughly $2.3 million, from Google in exchange for not releasing the data, and that it worked with actors associated with Scattered Spider to gain initial access.
Breach Timeline
June 2025: Threat actors posing as IT support tricked a Google employee into authorizing a malicious version of Salesforce's Data Loader, allowing data to be exfiltrated from a corporate Salesforce instance.
August 8, 2025: Google completed email notifications to affected businesses after terminating the attackers' access and carrying out an impact analysis, as reported by Cyber Daily and SC Media.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses, phone numbers, and home addresses.
Google's own breach notification, shared with BleepingComputer, describes the exposed data as basic business contact information and related notes, including business names, phone numbers, and notes left for sales agents planning follow-up contact. Google stated that payment information was not exposed and that no data in Google Ads accounts, Merchant Center, Google Analytics, or other advertising products was affected.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Because the stolen records involve businesses rather than consumer accounts, the most likely harm is targeted fraud aimed at those businesses. Attackers holding company names, phone numbers, and internal sales notes can pose convincingly as Google Ads sales representatives or IT support, since the notes contain context that makes such calls sound legitimate. This pattern has already been observed: reporting indicates the stolen Salesforce data fueled follow-on phishing and vishing campaigns.
For individuals whose contact details appear in the records, the risks include unsolicited phishing calls, text messages, and email designed to extract payments, credentials, or access to business systems. Recipients should treat any call or message claiming to come from Google Ads or Google sales staff with caution, especially when it involves payments, software installations, or account changes.
What Is Google (Partial) Doing in Response?
Google cut off the attackers' access quickly after discovering the activity, completed an impact analysis, and notified affected businesses by email. The company stated that the intruders had only a small window of access and that it has strengthened its security since the incident. Salesforce told BleepingComputer that its platform itself was not compromised and that the attacks resulted from phishing and social engineering rather than any known vulnerability in its software.
What Should You Do If You Were Affected?
If your business received a notification from Google or you believe your company's details were in the affected Salesforce instance, take these steps:
Be suspicious of unexpected calls or emails claiming to be from Google Ads, Google sales teams, or IT support, especially any request to install software or approve an application.
Verify identities through official channels before sharing any information. Hang up and contact the company through a number you look up independently.
Do not approve unfamiliar connected apps or authorization prompts in business tools such as Salesforce.
Train staff who handle inbound calls, since this attack succeeded through a human conversation rather than a technical flaw.
Report suspected fraud attempts to your internal security team and to the impersonated company.
In the news
- BleepingComputer – Google confirms data breach exposed potential Google Ads customers' infobleepingcomputer.com (opens in a new tab)
- Cyber Daily – Google's Salesforce instance hit in ShinyHunters cyber attackcyberdaily.au (opens in a new tab)
- SC Media – Remember: a simple phone scam compromised Google's Salesforce databasescworld.com (opens in a new tab)
