Advisory 96: Google vulnerability
Release Date: 30th of August 2025
Impact : HIGH / CRITICAL
TLP Rating: Clear
CERT Vanuatu (CERTVU) and the Department of Communication and Digital Transformation (DCDT) provide the following advisory.
This alert is relevant to Organizations who utilize the above products. This alert is intended to be understood by technical users and systems administrators.
What is it?
CERTVU would like to advise on the following;
In June 2025, threat actors from an entity known as UNC6040 (also functioning as ShinyHunters) achieved a successful infiltration of one of Google’s corporate Salesforce systems. This system contained business contact details and sales notes for small and medium-sized enterprises. Although no Gmail or Google Drive passwords or financial information were disclosed, the breach increased the vulnerability to targeted phishing campaigns utilizing the compromised contact data.
What are the Systems affected?
- The compromise did not extend to consumer services, meaning Gmail and other end-user products were directly breached.
- However, data derived from the Salesforce breach is now being weaponized to launch phishing (email-based) attacks aimed at Gmail users.
What this means?
- Attackers have crafted compelling campaigns, impersonating Google staff or IT support to trick users into resetting passwords and divulging 2FA codes.
- Vishing calls from legitimate phone numbers and area codes – ultimately leading to account takeovers
- There is growing concern that ShinyHunters may escalate tactics by launching a data leak site or engaging in extortion campaigns using the stolen contact data.
Mitigation process
CERT Vanuatu advises all Google/Gmail users to safeguard their Gmail accounts against emerging threats and strongly recommends the following precautions:
- Change your Gmail password immediately.
- Enable two-factor authentication (2FA)
- Remain alert to Phishing and vishing attempts
References
- https://cybersecuritynews.com/gmail-users-password-reset/?fbclid=IwY2xjawMhxyNleHRuA2FlbQIxMABicmlkETFvV1ZRYmNpNk1ZNnFCSmk3AR50Cx4of2J_jWdg25cGrq0xI-D1mtFTfYyKvEL5zmxKTl324iqCnC81yw4-iQ_aem_WtQYJ2E3zRWd8rrMiCZr9Q
- https://news.trendmicro.com/2025/08/26/google-data-breach-gmail/
- Download advisory (English): Google vulnerability