Google employee deceived, millions of files stolen! 2.5 billion Gmail users targeted
The cyber hacker group ShinyHunters gained access to the company's database managed via Salesforce by deceiving a Google employee.
Data belonging to millions of Google users has been targeted by a hacker group called ShinyHunters. It has been revealed that the hackers infiltrated a Salesforce-based system by deceiving an employee.
As reported by NTV, although the stolen files do not directly contain passwords, it has been reported that phishing attempts have increased due to the compromise of users' email and phone information.
SYSTEM ACCESS VIA EMPLOYEE CREDENTIALS
In the attack carried out in June, it was learned that the hacker group gained access to the system by obtaining the login credentials of a Google employee. In this way, millions of business files managed through Salesforce's cloud infrastructure were copied.
Although Google stated that user passwords were not compromised in the incident, it acknowledged that customer contact information was stolen.
SCAMMERS POSE AS GOOGLE EMPLOYEES
Cybersecurity expert James Knight emphasized that the attack seriously endangers Gmail users. Speaking to the Daily Mail, Knight drew attention to fake phone calls in particular:
“There is a lot of vishing (voice phishing); people call, pretend to be from Google, and try to get login codes. Nine out of ten cases do not actually come from Google.”
CRITICAL SECURITY RECOMMENDATIONS FROM EXPERTS
Knight invited Gmail users to review their account security. Key recommendations include:
- Multi-factor authentication must be used.
- Strong and unique passwords should be preferred.
- Google security check-ups should be performed regularly.
- Codes should never be shared during suspicious calls or messages.
LIMITED STATEMENT FROM GOOGLE
In an announcement made in August, Google did not disclose how many users were affected. Company spokesperson Mark Karayan refrained from making a new comment on the incident. Furthermore, it is unknown whether the attackers demanded a ransom from Google.
“EMAIL ADDRESSES ARE WORTH THEIR WEIGHT IN GOLD”
According to experts, the email and contact information obtained by the attackers could generate significant revenue on the black market. Knight drew attention to the scale of the risk, saying, “These email addresses are truly worth their weight in gold. The hackers have made a lot of money for themselves.”
It is known that ShinyHunters has attacked many large companies in the past and has made a name for itself with various data breaches.
News Source: 12punto
Most Read
How the ISIS terrorist preparing for an attack in Istanbul was neutralized
Apple's foldable phone price tag to set a new record
YÖK launches investigation into 23 foundation higher education institutions
Two-day sale and collateral traffic in Gökçek family allegations
Another bankruptcy in the construction sector
Detention warrants for 31 lawyers, searches at 39 offices
Journalist Oya Lale Arslan detained
Footage emerges of Berhan Şimşek allegedly assaulting his former partner
Massive compensation claim against Acun Ilıcalı
New seizure order in the Süleymancılar investigation