Sunday, September 6, 2026

Google Hacked – Approx 2.5 Million Records of Google Ads Customer Data Leaked

Google has disclosed a significant data breach involving one of its corporate Salesforce instances, compromising customer data tied to its Google Ads platform.

Google has not revealed the exact number of people impacted, but according to ShinyHunters, who spoke with Cyber Security News, the breach exposed around 2.5 million records (Approx). Whether some of these entries are duplicates is still unknown.

The incident, detected in June 2025, was perpetrated by a financially motivated threat group tracked as UNC6040, known for its advanced voice phishing (vishing) tactics.

Google notified GBHackers News that the completed email notifications to affected customers on August 8, 2025, following an initial announcement on August 5.

The breached Salesforce instance stored contact information and related notes for small and medium businesses using Google Ads. According to Google’s Threat Intelligence Group (GTIG), the stolen data included basic, largely publicly available business information, such as:

  • Business names
  • Contact details (e.g., email addresses, phone numbers)
  • Related notes stored in the Salesforce instance

While Google has stated that the compromised data was limited in scope and primarily publicly accessible, the breach raises concerns due to the potential for this information to be used in subsequent extortion schemes.

The threat actor retrieved the data during a brief window before Google revoked access, though specific details on the volume of affected records were not disclosed.

According to a Cyber Security News report, ShinyHunters demanded 20 Bitcoins (approximately $2.3 million) from Google. However, the threat actor later claimed this was sent “for the lulz” rather than as a serious extortion attempt.

The Attack and Extortion Threats

The breach was executed by ShinyHunters, who also claim collaboration with threat actors associated with Scattered Spider, now referring to themselves collectively as “Sp1d3rHunters.”

This group is responsible for gaining initial access to targeted systems, enabling ShinyHunters to conduct data exfiltration from Salesforce environments.

The attackers used a modified version of Salesforce’s Data Loader application, authorized through sophisticated voice phishing (vishing) tactics where employees were deceived into approving a malicious connected app.

GTIG notes that the group has evolved its tactics, shifting to custom Python scripts and using Mullvad VPN IPs or TOR to mask their activities.

ShinyHunters has been linked to extortion efforts tracked as UNC6240, contacting victims via emails from addresses like shinycorp@tuta[.]com and shinygroup@tuta[.]com, demanding bitcoin payments within 72 hours.

GTIG warns that the group may escalate by launching a data leak site (DLS) to pressure victims, including those affected by the Google Ads breach.

Extortion attempts often occur months after the initial theft, suggesting collaboration with other actors to monetize stolen data.

The attack highlights UNC6040 refined methods, including the use of compromised accounts from unrelated organizations to register malicious apps and automated data collection via TOR.

GTIG also observed infrastructure overlaps with “The Com,” a loosely organized cybercrime collective, indicating potential shared tactics among associated actors targeting cloud platforms like Okta and Microsoft 365.

Google responded promptly, conducting an impact analysis and implementing mitigations to secure the affected Salesforce instance.

The company emphasizes that the breach stemmed from social engineering, not a vulnerability in Salesforce’s platform. To prevent similar incidents, GTIG recommends:

  • Least Privilege Access: Restrict permissions for tools like Data Loader, particularly the “API Enabled” permission.
  • Connected App Management: Implement allowlisting and restrict powerful permissions like “Customize Application” to trusted administrators.
  • IP Restrictions: Define trusted IP ranges to block unauthorized access from VPNs or TOR.
  • Salesforce Shield: Use transaction security policies and event monitoring to detect suspicious activities, such as large data downloads.
  • Multi-Factor Authentication (MFA): Enforce MFA universally and educate users on social engineering tactics to prevent MFA bypass.

Find this News Interesting! Follow us on Google NewsLinkedIn, & X to Get Instant Updates!

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Chainguard Hits 1 Billion Build Manifests With AI-Powered Software Supply Chain Security

Chainguard has surpassed 1 billion container build manifests, doubling...

Russian Hackers Deploy New HOOKEDGE Backdoor in Espionage Attacks Across Europe

Russian state-sponsored threat actor BlueDelta, also tracked as APT28,...

New Panzer Ransomware Hits 16 Victims Across 11 Countries With Data Theft and Encryption

Panzer ransomware has emerged as a new Ransomware-as-a-Service (RaaS)...

12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers

A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged...

Hackers Use Frontier AI Agents to Breach Enterprise Network in Under 10 Hours

A threat actor used frontier artificial-intelligence models and attack-specific...

CARS24 Data Breach Exposes 3,100 Customer Records, Leads Allegedly Sold for ₹1,000 Each

Used-car platform CARS24 has alleged that confidential information belonging...

Hackers Turn HiveMQ and Element Messenger Into Control Channels for Windows Backdoors

The financially motivated threat actor Toy Ghouls has expanded...

Related Articles

Recent News