Follow us on Google for more Moneywise news
Add us on GoogleIt sounds like the plot of a sci-fi crime thriller, but the latest major cyberhack is real.
Google revealed that a cybercriminal group known as the ShinyHunters hacked a database of their accounts through the cloud-based software provider Salesforce, exposing the roughly 2.5 billion Gmail and Google Cloud users worldwide to possible breaches.
Google’s Threat Intelligence Group (GTIG) said it first discovered a breach in June and, by August, became aware of bad actors using “overlapping tactics, techniques, and procedures” to access networks and accounts. Those tactics include social engineering, such as impersonating IT support reps in phone conversations, primarily targeting English-speaking users at multinational companies.
Thanks for subscribing!
The money news that actually matters.
By signing up, you accept Moneywise Terms of Use, Subscription Agreement, and Privacy Policy.
GTIG said the data obtained was “basic and largely publicly available business information” but warned that ShinyHunters “may be preparing to escalate their extortion tactics by launching a data leak site … likely intended to increase pressure on victims.”
In the past, GTIG tracked the group’s actions for months after branches and found their extortion techniques included “calls or emails to employees of the victim organization demanding payment in bitcoin within 72 hours.” The hacker group takes its name from the Pokémon franchise.
Geekspin noted that ShinyHunters has previously hacked the organizations AT&T Wireless, Mashable, Microsoft, Santander, Ticketmaster and Wattpad. Along with extorting their victims, the group also sells stolen databases on the dark web, adding further risk to anyone’s accounts.
How to protect your Google account now
To keep your Google account as secure as possible, the company advises taking several steps.
Start by updating your password and making it unique to your Google account. As AllThingsSecured.com notes, using the same password across multiple accounts — such as email, banking or social media — means if a hacker gains access to one, they can access them all. The site recommends using a trusted password manager to both create and store strong passwords.
Google also advises enabling two-factor authentication along with a security key or Google Prompt. Both add an extra layer of protection by requiring you to approve a login even if a hacker has your password.
The company recommends updating related Google and Android apps, browsers and operating systems to ensure you have the latest and most secure versions.
Be wary of suspicious messages by email, text, from websites or even phone calls. Google warns that hackers may pretend to be institutions, family members or colleagues to steal sensitive information.
Never click on suspicious links, especially those asking for personal information such as passwords. If you receive a message claiming to be from a bank, for example, search for the institution's website or phone number independently and contact them directly.
Must Read
- The ultra-rich use these 5 real estate strategies to build wealth while they sleep — you can start with just $100
- Here’s the average income of Americans by age in 2026. Are you keeping up or falling behind?
- Insurance companies profit most from drivers who auto-renew without shopping around. Comparing 100+ quotes takes 2 minutes and costs nothing
Join 250,000+ readers and get Moneywise’s best stories and exclusive interviews first — clear insights curated and delivered weekly. Subscribe now.
Signs your account has been hacked, and what to do
Online security data platform Cybersecurity Insiders says sudden changes to your Google password, unauthorized updates to your personal information or spam emails sent from your account could all signal a breach.
Forbes adds that strange financial activity on your Google Pay or Play accounts could also be a warning sign, in which case you should contact your financial institutions immediately. Changes to Google Drive, such as photos or videos being shared without your permission, may also indicate a hack.
If you believe you’ve been hacked, change your password and then conduct a Google Security Checkup to suss out any unwanted or fraudulent activity.
If you do find any suspicious activity, Cybersecurity Insiders suggests contacting anyone who may have been affected, such as contacts who received spam from your account, and closely monitoring your account going forward.
You May Also Like
- JP Morgan sees gold hitting $6,000/oz before 2027 — and a Gold IRA lets you hold the physical metal while deferring the tax bill. Get your free guide from Priority Gold
- Dave Ramsey warns nearly 50% of Americans are making 1 big Social Security mistake — here’s what it is and the simple steps to fix it ASAP
- Thanks to Jeff Bezos, you can now become a landlord for as little as $100 — and no, you don't have to deal with tenants or fix freezers. Here's how
- Millionaires under 43 are reshaping investing — just 25% of their portfolios are in stocks. Here’s where their money is going
Mike Crisolago is a Sr. Staff Reporter at Moneywise with nearly 20 years of experience working as a journalist, editor, content strategist and podcast host. He specializes in personal finance writing related to the 50-plus demographic and retirement, as well as politics and lifestyle content.
