Google was among the organisations affected by the 2025 SaaS-platform campaign, with reporting putting exposed records at approximately 2.55 million.
This Is The Most Useful Data Point In The Campaign
The corpus routinely attributes incidents to under-resourcing: the funding gap at 25-1211, the workforce shortfall at 25-1209, the small law firms at 25-0910 and the nursery group at 25-0926.
That explanation is unavailable here. Whatever the constraint was, it was not budget, headcount, expertise or tooling.
The technique reached an organisation with essentially unlimited capacity to defend against it, which is strong evidence that the vulnerability is structural — the consent model at 25-0311, where a security decision is routed to whoever happens to be logged in.
It Also Constrains What The Corpus Can Recommend
If the best-resourced organisation in the database was reached by a phone call and an authorisation dialogue, then advice framed as "invest more" is inadequate.
What follows is narrower and less satisfying: administrative consent requirements, connected-application inventories, and out-of-band verification of any request that changes authorisation — the controls at 25-1207 and 25-0602 that cost little and are repeatedly absent everywhere, including where money is not the constraint.
On The Figure
Graded medium. 2.55 million records is as reported and this desk has not established what the records were, whether they concerned individuals or business contacts, or how the company characterised them.
The argument above does not depend on the number being exact. It depends on the incident having happened at all.
Compiled from published breach compilations, listed below. Record composition is not established. Corrections: corrections@forensicpost.com.