Google Data Breach History
WebsiteGoogle LLC is an American technology company (search, cloud, YouTube). Part of Alphabet Inc.
This page shows all data breaches of Google. View the complete breach timeline, records exposed, root causes, and AI breach risk score. BreachHistory tracks disclosed data breaches worldwide.
Data Breach Timeline — All Google Breaches
- 2025 2025 Google — Salesforce CRM breach via UNC6040/ShinyHunters vishing wave Unknown records Share
- 2023 2023 Google data breaches — full timeline Unknown records Share
- 2020 Australia — accused of misleading users on privacy (data combination) Unknown records Share
- 2020 $5B lawsuit — tracking in 'private' browsing Unknown records Share
- 2020 2020 — YouTube: Poor security / misconfiguration, 4,000,000 records 4.0M records Share
Google Data Breach Summary
This page tracks the Google data breach history and cybersecurity incidents affecting Google (United States). BreachHistory currently indexes 20 publicly disclosed or catalogued incidents spanning 2007 through 2025, with approximately 2.1 billion records reported as exposed across all indexed events. These totals may include overlapping datasets or third-party estimates and should not be interpreted as unique affected users.
The Google breach timeline includes major data breaches, cyber attacks, data leaks, credential exposures, API abuse, and other security incidents. Each incident provides details on the estimated records exposed, attack method, affected data types, and supporting public sources. Currently, 0 incidents are company-confirmed, while 2 remain unverified claims pending independent verification.
Largest Google Data Breaches
The largest indexed incidents include the 2018 Location data on 2B users — sometimes without permission, the 2018 Google+ API bug exposes 52.5M users, and the 2014 Nearly 5M Gmail addresses and passwords leaked online, along with additional historical incidents involving exposed passwords, public databases, and large-scale data scraping. Record counts originating from threat actors or leak sites should be treated as estimates unless confirmed by Google or a regulator. Below is the list of large data breaches:
- 2018 Location data on 2B users — sometimes without permission — about 2.0B records exposed · Catalogued incident
- 2018 Google+ API bug exposes 52.5M users — about 52.5M records exposed · Catalogued incident
- 2014 Nearly 5M Gmail addresses and passwords leaked online — about 5.0M records exposed · Catalogued incident
- 2020 2020 — YouTube: Poor security / misconfiguration, 4,000,000 records — about 4.0M records exposed · Catalogued incident
- 2016 Gooligan malware — 1M+ Android devices — about 1.0M records exposed · Catalogued incident
- 2015 BrainTest malware on Play Store — up to 1M Android devices — about 1.0M records exposed · Catalogued incident
- 2018 Google+ bug — 500k users' private data to developers (2015–2018) — about 500.0K records exposed · Catalogued incident
- 2018 2018 — Google: According to a press release, Alphabet Inc, 500K records — about 500.0K records exposed · Catalogued incident
What Information Was Exposed?
Depending on the incident, exposed data may include email addresses, passwords and login credentials, names, physical addresses, health and medical (PHI) records, and other personal information (PII). The exact data varies between incidents, so review each breach page before assuming your information was affected.
Google Data Breach 2026
At the time of this update, no Google data breach has been catalogued for 2026. New incidents are added as official disclosures, regulatory filings, or credible cybersecurity reports become available.
What To Do If You Were Affected
If you believe your account may have been involved in a Google data breach, change any reused passwords, enable multi-factor authentication (MFA), monitor your account for suspicious activity, and be cautious of phishing emails or fake breach notifications.
This Google breach history is maintained by BreachHistory using public disclosures, regulatory filings, security research, and clearly labelled third-party claims. For the complete breach timeline, records exposed, incident details, and AI Breach Risk Score, explore the sections on this page.