Google Suffers Data Breach, Puts Out Gmail Warning
Key topics
A supposed Google data breach has sparked a lively debate, with some commenters pointing out that the alleged breach actually originated from a Salesforce database hack. As users weighed in, it became clear that the real concern was a phishing scam leveraging the compromised data, with one user sharing a suspicious "delivery failure notification" that was DKIM signed and looked legitimate, but contained a dubious "click here to fix" link. Meanwhile, others chimed in to highlight Google's lack of customer-facing telephone support, making it unlikely that the company would call users out of the blue to warn them about security issues. The discussion also touched on the tendency to deflect blame onto more popular brands during security breaches.
Snapshot generated from the HN discussion
Discussion Activity
Light discussionFirst comment
50m
Peak period
2
0-1h
Avg / period
1.3
Key moments
- 01Story posted
Aug 26, 2025 at 8:54 PM EDT
4 months ago
Step 01 - 02First comment
Aug 26, 2025 at 9:44 PM EDT
50m after posting
Step 02 - 03Peak activity
2 comments in 0-1h
Hottest window of the conversation
Step 03 - 04Latest activity
Aug 27, 2025 at 10:39 AM EDT
4 months ago
Step 04
Generating AI Summary...
Analyzing up to 500 comments to identify key contributors and discussion patterns
Want the full context?
Jump to the original sources
Read the primary article or dive into the live Hacker News thread when you're ready.
If your brand is more popular than the vendor’s, it is called, you should have known better to not use such unknown brand. Your choice of vendor is your responsibility.
If both you and your vendors are popular, it’s up to the narrative to place blame.
Thats why most large companies still refuse to buy from small brands.
Users were alerted to the scheme when they realized Google has no functioning customer-facing telephone support.
Google suffers data breach in ongoing Salesforce data theft attacks
https://news.ycombinator.com/item?id=44812198
Probably related to this since it had a 'click here to fix' link that went to some aws url.
Of course, since Google never contacts you except when they want to slurp more personal data out of you [1], it was suspicious from the start.
[1] See what happened when I tried to recover an old unused gmail account:
https://news.ycombinator.com/item?id=44952830