Google said it was not hacked and a Gmail username and password list with more than 5 million accounts was harvested over time. It seems most likely that the email usernames and passwords were taken due to phishing scams and by trying to log into hacked websites, according to security experts.
"We're always monitoring for these dumps so we can respond quickly to protect our users," the Google security team said in a blog post following news of the username/password leak. "We found that less than 2% of the username and password combinations might have worked, and our automated anti-hijacking systems would have blocked many of those login attempts. We've protected the affected accounts and have required those users to reset their passwords."
Google recommends two-step verification anytime a Gmail user logs into an account from a new device or IP address. Users should also regularly change passwords and ensure they are using different passwords for their online bank accounts, email, and social networking websites.