A highly suspicious article came across my screen. It claimed:
As Many as 5 million Gmail Usernames and Passwords Leaked
According to The Daily Dot, as many as 5 million Gmail usernames and passwords were reportedly leaked on a Russian Bitcoin forum.
The route of the leak is unknown, but the leaked data apparently concerns English-, Russian-, and Spanish-speaking users of Google services such as Gmail and Google+.
(Source) MAC Otakara’s Blog: “As Many as 5 million Gmail Usernames and Passwords Leaked” [1]
Wait a moment. If this came from Google, 5 million is far too few. There are 1 billion users. If someone gained database access, it is inconceivable that they would take only 0.5%. The language-specific nature of the data is also highly suspicious. It was probably phishing. Thinking that, I checked the original Daily Dot article [2]. Sure enough, it quoted Google as saying that many entries were for very old accounts that no longer existed or had been suspended, and that they were probably obtained through phishing. I then checked the underlying Russian-language forum post [3], which said that the circumstances indicated phishing. So the original was levelheaded. The story merely became more extreme as it was republished.
Sensationalism is not acceptable!
The article says you can test whether your information leaked at isLeaked.com, but I recommend verifying that isLeaked.com is legitimate before trying it, just as a word of caution. Incidentally, Google’s official blog said that valid email-address and password combinations accounted for less than 2% [4].
[1] MAC Otakara’s Blog: “As Many as 5 million Gmail Usernames and Passwords Leaked” http://www.macotakara.jp/blog/news/entry-24544.html (accessed 2014/9/11)
[2] The Daily Dot: “5 million Gmail passwords leaked to Russian Bitcoin forum,” http://www.dailydot.com/crime/google-gmail-5-million-passwords-leaked/ (accessed 2014/9/11)
[3] А теперь и gmail.com: в сеть выложена база на 5 000 000 адресов http://habrahabr.ru/post/236283/
[4] http://googleonlinesecurity.blogspot.jp/2014/09/cleaning-up-after-password-dumps.html
[*] Incidentally, the Nikkei BP article was, as expected, properly written. http://itpro.nikkeibp.co.jp/atcl/news/14/091100836/
Related posts
Reflections on the US Yahoo! Password Leak
(UPDATE 1) Yahoo! Voice and Yahoo! Voices appear to be different services, so I updated that point. The conclusion remains unchanged—which means Yahoo! Voice should also…
Passmark Is Not Phishing-Resistant Either
Passmark is a technology that displays an image configured by the user when the user logs in to a website, allowing the user to distinguish a…
Two-Factor Authentication Using a Bookmark: BeamAuth
One weakness of OpenID is the problem of phishing. With OpenID, users are redirected to an authentication server for authentication. The problem is that, instead of…
