The Gmail bomb hoax investigation in Gujarat has uncovered what police describe as credentials for 513,847 email accounts, but that number does not by itself mean Gmail was breached or that more than half a million ordinary users were hacked.
Police-attributed reporting says investigators recovered a list containing 5,13,847 email IDs and corresponding passwords while examining an alleged cybercrime network linked to bomb-threat emails and other abuse. Reuters later reported that investigators intend to question Google about how such a large number of Gmail accounts could have been created or operated and about the safeguards around those accounts.
Direct answer: Current evidence supports a large alleged Gmail account-abuse network and a major credential trove. It does not establish a Gmail infrastructure breach, compromise of 513,847 ordinary Gmail users or a technically proven mass bypass of Google 2-Step Verification.
What does the 513,847 figure actually represent?
The figure comes from the credential inventory described by Gujarat Police during the investigation. Current reporting says investigators recovered 513,847 unique email IDs and corresponding passwords.
That is not the same as proving that every account sent a bomb-threat email. Police were still examining which accounts had actually been used for threats or other cybercrime.
The distinction matters because a recovered credential database can contain accounts created for abuse, accounts held for later use, accounts sold to others or accounts whose exact activity has not yet been established.
Does this mean Gmail itself was hacked?
No Gmail platform breach has been established by the evidence reviewed for this article.
The investigation concerns a large alleged network of Gmail accounts or credentials controlled or traded for cybercrime purposes. That is different from evidence showing attackers penetrated Google’s Gmail infrastructure or extracted hundreds of thousands of unrelated users’ passwords from Google systems.
No evidence reviewed by TPS establishes that 513,847 ordinary Gmail customers had their existing personal accounts stolen.
Were all 513,847 accounts used for bomb threats?
No such conclusion has been established.
The bomb-hoax investigation led police to the wider credential network, but current reporting says investigators are still determining which IDs were actually used for bomb threats, other cybercrime or other purposes.
Readers should therefore avoid turning the recovered-account count into a count of confirmed threat emails, confirmed offenders or confirmed victims.
What does the reported 2FA detail mean?
Reuters reported that a senior Gujarat cybercrime official said the fraudulent accounts employed two-factor authentication. That detail is important, but it needs careful interpretation.
Google’s 2-Step Verification is an additional sign-in layer. After it is enabled, signing in can require the password plus another verification method.
An account can therefore have 2-Step Verification enabled while still being controlled by a criminal operator who possesses both the password and the second factor. The mere presence of 2FA does not prove that the 2FA system itself was technically defeated.
Did the network bypass Google 2FA?
This remains an unresolved technical question.
Some police-attributed reporting describes the network as having bypassed authentication safeguards, including Google Authenticator or two-factor authentication. Reuters, however, presented the mechanism as part of the continuing investigation into how the accounts were created and operated at this scale.
Without a Google technical response or account-level forensic evidence explaining the mechanism, TPS is not treating a mass 2FA bypass as an established fact.
Possible states can be very different: operators could have controlled both passwords and second factors, used accounts registered with numbers or devices under their control, obtained credentials from another source, abused weaknesses in account-creation controls, or used some other method investigators have not yet publicly established.
Is phone verification during Gmail account creation the same as 2FA?
No.
Google may ask for phone verification while an account is being created to help confirm that the person creating the account is not an automated system. Google 2-Step Verification is a separate security feature used during later sign-ins.
This distinction is important because reports questioning how the accounts passed creation or phone-verification controls should not automatically be rewritten as proof that Google’s 2-Step Verification was broken.
Does Google require a phone number for every new Gmail account?
Google’s own account-help documentation does not state that every account creation always requires a phone number. It says Google may ask users to verify by phone in some situations.
That means the existence of hundreds of thousands of accounts cannot, from current evidence alone, prove that hundreds of thousands of unique phone numbers were necessarily used or that one particular verification mechanism was defeated in every case.
Why does Gujarat Police want to question Google?
Reuters reported that investigators intend to approach Google about safeguards around the accounts and possible changes that could reduce abuse.
The investigation is therefore moving beyond the existence of the recovered credential list toward questions about how the accounts were created, maintained and protected at scale.
A Google response could materially change the interpretation of this case. It could clarify whether the accounts were created through normal processes, whether verification systems were abused, whether the credentials came from another source, or whether Google identified a specific security-control weakness.
Should ordinary Gmail users reset their passwords because of this case?
Current evidence does not support telling every Gmail user to reset their password solely because of this investigation.
There is no reviewed evidence showing that unrelated ordinary Gmail accounts were compromised as part of the 513,847-account database.
Users should still respond normally to account-specific warning signs. If Google reports an unfamiliar sign-in, an unknown device appears in account activity, recovery information changes unexpectedly or other suspicious activity appears, review the account’s security settings and follow Google’s account-recovery and security guidance.
Using 2-Step Verification remains appropriate account-security practice; this investigation has not established that ordinary users should disable it.
What if you receive a bomb-threat email?
The account-security question is separate from the public-safety response to a threat email.
If an organisation or individual receives a bomb-threat message, preserve the message and relevant technical evidence and report it promptly to the appropriate police or security authorities. Do not engage with the sender or assume that identifying the Gmail address establishes the sender’s real identity.
What the investigation has established — and what it has not
| Claim | Current evidence state |
|---|---|
| Police recovered credentials for 513,847 email accounts | Strongly police-attributed and corroborated |
| The wider investigation is linked to bomb-hoax emails and other alleged cybercrime | Police-attributed |
| All 513,847 accounts sent bomb threats | Not established |
| 513,847 ordinary Gmail users were hacked | Not established |
| Gmail infrastructure was breached | Not established |
| The accounts reportedly used two-factor authentication | Reported by Reuters from a senior police official |
| Google 2FA was technically bypassed at scale | Not technically established; some police-attributed reports allege bypass |
| Police intend to question Google | Reported by Reuters |
Why the difference matters
Five statements that may sound similar describe very different security events:
- Someone created large numbers of accounts for abuse.
- Someone controlled passwords for those accounts.
- The accounts had 2FA enabled.
- Someone compromised legitimate users’ existing accounts.
- Someone breached Google’s Gmail infrastructure or defeated its authentication system.
The current investigation strongly supports the first two states and reports the third. It does not yet establish the fourth or fifth.
That evidence boundary is the most important thing ordinary Gmail users need to understand from the 513,847-account figure.
What happens next?
The next material evidence should come from one or more of four places: a Google response, additional Gujarat Police or Cyber Centre of Excellence forensic findings, chargesheet or court material describing the account-generation mechanism, or evidence identifying how many accounts were actually used for bomb threats and other offences.
If investigators establish that a Google security control was technically bypassed, that would materially change the current answer. If Google instead establishes that the operators legitimately controlled the passwords and second factors for purpose-created accounts, that would point toward large-scale platform abuse rather than compromise of unrelated Gmail users.
Verification note
ThePulseSignal reviewed Reuters’ direct reporting from senior Gujarat cybercrime official Vivek Bheda, police-attributed reporting from Indian Express, New Indian Express, Times of India, ThePrint and India Today, and Google’s own documentation explaining 2-Step Verification and account-creation phone verification. The direct Gujarat Police/CCoE release URL and Google’s case-specific response were not available in the reviewed evidence.
Limitations and unresolved facts
The exact account-creation mechanism, validity and current status of every credential, number of accounts actually used for bomb threats, ownership history of the accounts, role of individual phone numbers or devices, exact second-factor mechanism and whether any Google security control was technically bypassed remain unresolved. TPS also does not treat allegations concerning foreign links, cryptocurrency or other participants as proven beyond the current police investigation and reporting.