A highly suspicious article came across my screen. It claimed:
As Many as 5 million Gmail Usernames and Passwords Leaked
According to The Daily Dot, as many as 5 million Gmail usernames and passwords were reportedly leaked on a Russian Bitcoin forum.
The route of the leak is unknown, but the leaked data apparently concerns English-, Russian-, and Spanish-speaking users of Google services such as Gmail and Google+.
(Source) MAC Otakara’s Blog: “As Many as 5 million Gmail Usernames and Passwords Leaked” [1]
Wait a moment. If this came from Google, 5 million is far too few. There are 1 billion users. If someone gained database access, it is inconceivable that they would take only 0.5%. The language-specific nature of the data is also highly suspicious. It was probably phishing. Thinking that, I checked the original Daily Dot article [2]. Sure enough, it quoted Google as saying that many entries were for very old accounts that no longer existed or had been suspended, and that they were probably obtained through phishing. I then checked the underlying Russian-language forum post [3], which said that the circumstances indicated phishing. So the original was levelheaded. The story merely became more extreme as it was republished.
Sensationalism is not acceptable!
The article says you can test whether your information leaked at isLeaked.com, but I recommend verifying that isLeaked.com is legitimate before trying it, just as a word of caution. Incidentally, Google’s official blog said that valid email-address and password combinations accounted for less than 2% [4].
[1] MAC Otakara’s Blog: “As Many as 5 million Gmail Usernames and Passwords Leaked” http://www.macotakara.jp/blog/news/entry-24544.html (accessed 2014/9/11)
[2] The Daily Dot: “5 million Gmail passwords leaked to Russian Bitcoin forum,” http://www.dailydot.com/crime/google-gmail-5-million-passwords-leaked/ (accessed 2014/9/11)
[3] А теперь и gmail.com: в сеть выложена база на 5 000 000 адресов http://habrahabr.ru/post/236283/
[4] http://googleonlinesecurity.blogspot.jp/2014/09/cleaning-up-after-password-dumps.html
[*] Incidentally, the Nikkei BP article was, as expected, properly written. http://itpro.nikkeibp.co.jp/atcl/news/14/091100836/
Related posts

I Will Appear on the Okinawa Open Days Panel “Current and Future OSS Initiatives in Economic Security”
It is already the day of the event—in fact, I am writing this now (12/4 9:45) at my desk while preparing for the panel—but I will…

The “DS-511 Guidelines for Handling Digital Identity in Identity Verification for Administrative Procedures, etc.” Have Been Published
After 3 years of development, the Digital Identity Guidelines, to which I had the privilege of contributing as an expert (Expert Meeting on the Revision of…

Age Verification: The UK Online Safety Act Is Being Toyed With in All Kinds of Ways—Bypassing It With VPNs and Evading Biometrics With Death Stranding
What Is the UK's Online Safety Act? The UK's Online Safety Act formally became law after receiving Royal Assent on October 26, 2023, and came into…
