New analysis of the Have I Been Pwned platform revealed that more than 183 million email credentials, including accounts of Gmail, Este Vast cybersecurity incident exposes significant amount of user data.
The exposure of this sensitive data, which includes email addresses and passwords, is attributed to the action of Infostealers. Estes are malicious programs specifically designed to infect devices and silently capture personal information.
The initial discovery of this data compromise occurred in April 2025, and a recent update added 16.4 million records to the already alarming amount. The extent of the problem underscores the ongoing threat users face online.
Threat of infostealers and the extent of the leak
The Have I Been Pwned platform team detected the 16.4 million new records during a recent data analysis. Esses additional records had not been identified in the initial check carried out in April, bringing the total number of compromised credentials to an even more worrying level.
On the same topic: Massive cyber incident compromises more than 183 million Gmail, Outlook and Yahoo email accounts
The total number of 183 million credentials reflects a compilation of multiple incidents involving the action of Infostealers. Troy Hunt, creator of Have I Been Pwned, said other companies and online services also appear in the compiled records, although he did not publicly specify additional names. The theft technique occurs through infection in computers and cell phones.
Reaction from technology giants and silence
Google, one of the indirectly affected companies, reported that the exposed accounts do not belong exclusively to Gmail, indicating that the incident is the result of general malicious activity and not a direct attack on its systems. The company reinforced the importance of two-step verification and the use of passkeys, technologies that offer additional layers of robust security to its users to access accounts.
On the other hand, Microsoft and Yahoo did not officially comment on the case at the time of publication of this news. The lack of a position on the part of these companies maintains a silence that generates uncertainty among their users and in the cybersecurity community, which seeks to understand the real dimension of the compromise.
Essential protection: changing passwords and enabling double verification
Users who suspect their accounts are affected should immediately change their passwords on all online services involved. It is crucial to create unique and complex combinations for each platform, avoiding the repetition of credentials on different websites or applications.
Enabling two-step authentication (2FA) adds a robust layer of security to any digital account. Este method requires an extra code, usually sent to a mobile device or generated by an authenticator application, whenever new access is detected, making intrusions difficult.
Tools like password managers can simplify the process of creating and securely storing credentials. Eles generate strong passwords and store them encrypted, facilitating use without the need to memorize multiple complex combinations.
More on this story: Restarting iPhone Weekly Protects Against Invisible Malware, NSA Recommends
Furthermore, the adoption of access keys, based on biometrics or device PIN, eliminates dependence on traditional passwords. Empresas like Google, WhatsApp and Microsoft have already implemented this technology to improve security and user experience.
Understanding infostealers: how they act and what data they steal
Infostealers programs are malicious software that install themselves on devices, often through fraudulent downloads, suspicious links in emails or messages, or compromised email attachments. Once active, they operate discreetly, collecting a wide range of information without the user noticing any unusual activity.
These malware are designed to access data saved in browsers such as Chrome, Edge and Firefox, including stored passwords, session cookies, autofill information and, in some cases, credit card details. Eles can also collect data from applications and other sources on the infected system, seeking as much valuable information as possible.
Learn more: Android 17 brings threat alerts on mobile networks in the new beta version
The information collected by Infostealers is then compiled and often sold on clandestine forums on the dark web, an illicit market where cyber criminals use it for financial fraud, identity theft, unauthorized account access and other malicious attacks. Infostealers attacks can affect operating systems such as Windows, macOS, and various mobile devices, making vigilance a constant necessity.
Digital security recommendations for users
Always check the URL of websites before entering any credentials. Golpes phishing scams often use fake pages that imitate legitimate services to trick users into stealing their login information.
Emails or messages that request personal data without a clear and apparent reason should be treated with extreme suspicion. Evite click on links contained in unsolicited messages or from unknown senders, as they may lead to malicious websites.
Learn more: Hidden risk in public Wi-Fi networks: expert points out user vulnerabilities
Your passwords must be a minimum of 12 characters, combining upper and lower case letters, numbers and special symbols. Memorable Frases, with the replacement of some letters by numbers or symbols, can serve as the basis for strong and, at the same time, easy-to-remember combinations.
Tools to manage passwords and increase defense
Password managers such as LastPass, KeePass, 1Password or the built-in Google Chrome manager are essential tools for keeping digital credentials secure. Eles encrypt data locally or in the cloud, offering secure synchronization between different user devices.
[[_0]
These tools patch known vulnerabilities through regular updates and warn about weak or reused passwords, helping users keep their credentials secure. Using these solutions is a fundamental step towards strengthening your personal security posture against cyber threats like Infostealers, minimizing the risks of future leaks.

