Looking for a complete Google data breaches list? This page answers common searches like "Google hacked," "Google breach history," and "list of Google data breaches" with a verified timeline, record counts, root causes, and step-by-step guidance if you may have been affected.
Google data breach history: Location-data controversies, Google+ API bugs, and Gmail credential leaks show even search giants lose control of user data. BreachHistory indexes 20 verified or attested incidents tied to Google, spanning 2007–2025. This page is a complete, searchable timeline—not a single event—linking every catalog row with context on scale, root cause, and what users should do when a new Google notice drops.
Why Google stays on breach trackers
Global tech brands combine massive user bases, high-value intellectual property, and complex supply chains. Attackers target Google for credentials, source code, CRM exports, and employee directories. When you read headlines about "Google hacked," the incident may be a consumer PII leak, a developer artifact exposure, or a third-party SaaS tenant breach—each with different remediation steps.
Data breaches list — Google
Below are the major incidents in our catalog, newest first. Record counts use company, regulator, or Have I Been Pwned attestation where available; actor-only marketing shows as "Unverified / not disclosed."
- 2025 — Google — Salesforce CRM breach via UNC6040/ShinyHunters vishing wave (Unverified / not disclosed records)
- 2023 — Google data breaches — full timeline (Unverified / not disclosed records)
- 2020 — Australia — accused of misleading users on privacy (data combination) (Unverified / not disclosed records)
- 2020 — $5B lawsuit — tracking in 'private' browsing (Unverified / not disclosed records)
- 2019 — $170M FTC fine — YouTube Kids child data (Unverified / not disclosed records)
- 2018 — Google+ API bug exposes 52.5M users (52.5M+ records)
- 2018 — Alphabet (Google): According to a press release, Alphabet Inc, 500K records (500K+ records)
- 2018 — Google: According to a press release, Alphabet Inc, 500K records (500K+ records)
- 2018 — Location data on 2B users — sometimes without permission (2B+ records)
- 2018 — WSJ — third parties access Gmail (metadata and content) (Unverified / not disclosed records)
- 2018 — Google+ bug — 500k users' private data to developers (2015–2018) (500K+ records)
- 2017 — Google: Recently, many people received a phishing email… (Unverified / not disclosed records)
- 2016 — Gooligan malware — 1M+ Android devices (1M+ records)
- 2016 — Google: Google Inc (Unverified / not disclosed records)
- 2015 — BrainTest malware on Play Store — up to 1M Android devices (1M+ records)
Biggest and most consequential incidents
Location data on 2B users — sometimes without permission
Pausing 'location history' did not stop all location storage; data still in 'web and app activity.' Up to 2B users potentially affected. Full incident record →
Google+ API bug exposes 52.5M users
November update caused API bug exposing 52.5M Google+ accounts. Fixed in six days; Google+ shutdown moved up to April 2019. Full incident record →
Nearly 5M Gmail addresses and passwords leaked online
Almost 5M Gmail credentials published. Google said systems not compromised; password resets. Data may have been aggregated from other incidents. Full incident record →
Gooligan malware — 1M+ Android devices
Checkpoint found Gooligan infecting 13k devices daily via phishing and third-party app stores. Full incident record →
By the numbers (catalog snapshot)
- 20 incidents indexed under Google on BreachHistory
- 2.1B+ combined attested records across rows with disclosed numerators (many incidents overlap or count emails—not unique people)
- 2018 — year of the largest attested row in our catalog
Patterns in Google's breach history
- Credential and session theft — Phishing, stuffing, and OAuth token abuse recur across tech platforms.
- Cloud misconfiguration — S3 buckets, misconfigured APIs, and file shares expose data without a traditional "hack."
- Extortion without precise counts — Ransomware and leak-site actors often publish before victims confirm scope.
- Supply-chain spillover — npm, SDK, and CRM tenant breaches affect Google customers even when corporate HQ databases stay intact.
What to do if you used Google
- Enable multi-factor authentication on every Google account and linked SSO identity.
- Check Have I Been Pwned when new Google headlines appear.
- Rotate passwords that were reused on email, banking, or work SSO.
- Watch for phishing that cites real breach details (order numbers, usernames) to appear legitimate.
- Follow official Google security communications—not SMS links from unknown numbers.
Related searches
- Google data breach list
- Has Google been hacked?
- Google hack history
- Google data leak timeline
- How many times has Google been breached?
- Google breach records on BreachHistory
FAQ
How many data breaches has Google had?
BreachHistory indexes 20 verified or attested Google data breaches spanning 2007–2025. Counts vary when researchers merge scraping, misconfiguration, and ransomware as separate events.
What is the biggest Google data breach?
The largest attested incident in our catalog is 2B+ records (Location data on 2B users — sometimes without permission). See the full timeline for sources and remediation details.
Has Google been hacked?
Yes — Google appears on breach trackers with 20 indexed incidents including Location data on 2B users — sometimes without permission. This page links every catalog row with primary sources and what users should do if affected.
Does Google send data breach notifications?
Regulated markets require consumer notices for many PII events. Not every source-code or scraping story triggers email alerts—read each incident row for notification status.
Explore every Google incident on BreachHistory
Browse the full catalog: Google breach records
Compiled from BreachHistory data/breaches.json and primary sources linked on each incident page. Updated 2026-06-15.