2.5b Gmail Users Endangered After Google Database Hack
Posted5 months agoActive5 months ago
pcworld.comTechstory
skepticalnegative
Debate
70/100
GoogleData BreachCybersecuritySalesforce
Key topics
Google
Data Breach
Cybersecurity
Salesforce
A Salesforce instance used by Google was hacked, potentially exposing contact information, but the actual risk to Gmail users is disputed among commenters.
Snapshot generated from the HN discussion
Discussion Activity
Active discussionFirst comment
28m
Peak period
14
0-1h
Avg / period
5.3
Comment distribution16 data points
Loading chart...
Based on 16 loaded comments
Key moments
- 01Story posted
Aug 24, 2025 at 6:22 PM EDT
5 months ago
Step 01 - 02First comment
Aug 24, 2025 at 6:50 PM EDT
28m after posting
Step 02 - 03Peak activity
14 comments in 0-1h
Hottest window of the conversation
Step 03 - 04Latest activity
Aug 25, 2025 at 10:22 AM EDT
5 months ago
Step 04
Generating AI Summary...
Analyzing up to 500 comments to identify key contributors and discussion patterns
ID: 45008323Type: storyLast synced: 11/20/2025, 5:45:28 PM
Want the full context?
Jump to the original sources
Read the primary article or dive into the live Hacker News thread when you're ready.
Until it happens to them.
A quick search/prompt shows:
- Operation Aurora: <https://en.wikipedia.org/wiki/Operation_Aurora>
- 2010s global surveillance disclosures: <https://en.wikipedia.org/wiki/2010s_global_surveillance_disc...>
I'm dubious. This requires you give google a phone number. Almost universally if you give a company a phone number there is eventually an avenue for an attacker to convince the company to give them control of the account by demonstrating control of the number (which they've sim swapped or otherwise hijacked).
Even if at the moment there is no avenue to exploit google this way (also doubtful), all it takes is some new product (like workspaces) that has a different security understanding or new bugs to open a vector.
https://news.ycombinator.com/item?id=44812343
https://cloud.google.com/blog/topics/threat-intelligence/voi...
This PCWorld article seems to be taking that to mean that every single gmail account (2.5B) is at risk with nothing to support that claim.