← Blog

Google Data Breaches: Full Timeline Through 2026

Share on X

Google processes more personal data than almost any entity on Earth—Search, Gmail, Android, YouTube, Cloud. People search Google data breach timeline because the brand is synonymous with the internet itself. BreachHistory indexes 20 Google-linked incidents; this analysis covers verified disclosures, regulatory actions, and ecosystem malware through 2026.

Google breaches vs. privacy enforcement

Not every row is a hacker exfiltrating Gmail. Google's history includes API bugs (Google+), regulatory fines (YouTube COPPA, location tracking litigation), third-party app access, and nation-state spear phishing (Operation Aurora). We label each accordingly.

Timeline through 2026

2025 — Salesforce CRM vishing (ShinyHunters wave)

Google confirmed a June 2025 Salesforce instance breach during the UNC6040 voice-phishing campaign linked to ShinyHunters extortion. Google said stolen data was largely SMB contact fields—not consumer Gmail mailboxes. Still critical for B2B phishing and supply-chain trust.

2020 — YouTube misconfiguration and privacy litigation

BreachHistory indexes a 4M-record YouTube misconfiguration row plus major privacy cases: $5B incognito tracking lawsuit and Australian privacy combination allegations. These shape compliance more than credential theft.

2019 — YouTube COPPA and credential leaks

FTC fined Google $170M over YouTube Kids data collection. Separately, 5 million Gmail addresses and passwords circulated online—mostly reused credentials from other sites, but Gmail users faced stuffing attacks.

2018 — Google+ API disasters

Two API bugs defined the year: a 2015–2018 Google+ flaw affecting 500k users Google failed to disclose promptly, and a November update bug exposing 52.5 million users. Google+ shut down. Location-tracking reporting claimed 2 billion users' location data was collected despite privacy settings—a policy scandal with breach-like harm.

WSJ reported third-party Gmail access including message content for app review programs—raising supply-chain trust issues predating 2025 Salesforce incident.

2016–2017 — Gooligan Android malware and phishing

Gooligan malware rooted 1M+ Android devices via rogue apps. 2017 Gmail phishing campaigns targeted users with fake Google Docs links—credential theft at scale without Google server compromise.

2015 — Play Store malware

BrainTest infected up to 1M Android devices through malicious Play Store apps—Google's curation failure mode.

2009 — Operation Aurora

Chinese state hackers spear-phished Google employees in the Operation Aurora campaign—intellectual property theft that triggered Google's exit from mainland China search. Foundational moment for modern APT reporting.

2007–2013 — Early catalog rows

Earlier indexed incidents include malvertising, user notifications, and Chrome unintended disclosure rows—smaller in scale but part of the complete archive.

Risk themes for Google users

  • OAuth third parties: Review connected apps in Google Account permissions.
  • Android sideloading: Gooligan/BrainTest show Play Protect isn't perfect—avoid unknown APKs.
  • Workspace admins: Salesforce/OAuth integrations are now prime vishing targets post-2025.
  • Location & ad data: Regulatory rows highlight harms even without classic "hacks."

Action checklist

  1. Run Google Account permissions review.
  2. Enable 2-Step Verification with passkeys where supported.
  3. Use Advanced Protection Program for high-risk accounts.
  4. Audit Google Workspace OAuth apps if you're an admin.

Canonical hub: breachhistory.com/google · 2025 CRM row: Google Salesforce vishing 2025