Proper news from Britain - News from Britain you won’t find anywhere else. Not the tosh the big media force-feed you every day!

Gmail users have been urged to check their accounts after it was revealed that more than 183 million passwords were stolen in a data breach.  

Australian cyber expert Troy Hunt, who revealed the incident, called it a 'vast corpus' of breached data, which totals 3.5 terrabytes. 

To put that into perspective, that's the equivalent to 875 full-length HD movies. 

According to Mr Hunt, 'all the major providers have email addresses in there' – so not just Gmail, but Outlook, Yahoo and others too.

'They're from everywhere you could imagine, but Gmail always features heavily,' Hunt told the Daily Mail. 

So have you been caught up in the incident?

Here's how to check if your email data has been compromised. 

It's the email provider of choice for around 2 billion people worldwide. But Gmail has been involved in a huge data breach affecting more than 183 million user accounts

The incident occurred in April but has only just been disclosed on Mr Hunt's Have I Been Pwned (HIBP) website. 

According to the expert, breached data contained 183 million unique email addresses alongside the websites they were entered into and the passwords used. 

To check if you've been compromised, head to the Have I Been Pwned website and enter your email address in the search bar. 

Next, tap on the button marked 'Check' and the site will show you the list of data breaches affecting your email address.

Even if not included in the recent Gmail breach, your details may have been involved in past breaches going back over a decade. 

If you are one of the 183 million people affected in this latest incident, you need to change your email password as soon as possible. 

Once this is done, enable two-factor authentication (2FA) if you haven't already – which sends a code to your smartphone to get into your online accounts.

According to Mr Hunt, this incident is not a single breach but a collection of 'stealer logs' – a series of data files generated and compiled by 'malware' (malicious software).

To check if you've been compromised, head to the Have I Been Pwned website and enter your email address in the search bar

How to check if you're affected 

  1. Head to Have I Been Pwned
  2. Enter your email address in the search bar and tap 'Check' 
  3. Check the list of breaches involving your email address
  4. Change your password if it has been involved in a breach

'Stealer logs are more of a firehose of data that's just constantly spewing personal info all over the place,' Mr Hunt explained in his blog post. 

'Once the bad guys have your data, it often replicates over and over again via numerous channels and platforms.' 

As yet, there's no word on the identify of the criminals responsible for the malware, however. 

The expert stressed that it's not just the password associated with your email account that has been potentially compromised. 

Also at risk are the unique passwords associated with your email address that you use on other websites too, such as Amazon, eBay and Netflix. 

He added: 'Stealer logs expose the credentials you enter into websites you visit then login to.' 

Therefore, if you find your email address under Have I Been Pwned it would be worth changing your password on any platform that uses it. 

Generally, people put themselves at greater risk by using the same single password across all their various online accounts. 

Graham Cluley, a computer expert and security blogger, said people should 'always use different passwords' for different online accounts.

'You won't be able to remember them by yourself, so use a password manager to do it for you,' Mr Cluley told the Daily Mail. 

'Always enable multi-factor authentication when available for a higher level of protection.

'We're not talking about one company getting hacked, but millions of people unknowingly having their passwords stolen through malware.

'With 183 million email addresses exposed, it's possible that many people could be caught up in this without even realising their computers have been compromised.' 

Benjamin Brundage at cybersecurity platform Synthient, which 'detects and blocks bad actors', was the one that discovered the breached data and sent it to HIBP. 

Mr Brundage – who is in his final year of college in the US – advised users not to assume they are safe simply because they use strong passwords, which are considered the first line of defence against cyber incidents. 

A strong password is at least 16 characters long and includes a mix of capital and lowercase letters as well as numbers and symbols. 

What is Have I Been Pwned? 

Cybersecurity expert and Microsoft regional director Tory Hunt runs 'Have I Been Pwned'.

The website lets you check whether your email has been compromised as part of any of the data breaches that have happened. 

If your email address pops up you should change your password. 

Pwned Passwords 

To check if your password may have been exposed in a previous data breach, go to the site's homepage and enter your email address. 

The search tool will check it against the details of historical data breaches that made this information publicly visible. 

If your password does pop up, you're likely at a greater risk of being exposed to hack attacks, fraud and other cybercrimes. 

Mr Hunt built the site to help people check whether or not the password they'd like to use was on a list of known breached passwords. 

The site does not store your password next to any personally identifiable data and every password is encrypted.

Other Safety Tips 

Hunt provides three easy-to-follow steps for better online security. 

First, he recommends using a password manager, such as 1Password, to create and save unique passwords for each service you use. 

Next, enable two-factor authentication. Lastly, keep abreast of any breaches.

Adblock test (Why?)