Always verify the sender's email address. Google will never ask you to "verify your account" via a random link in an email. Hover over links before clicking. When in doubt, type myaccount.google.com directly into your browser.
Most public credential lists come from breaches at other websites (like retail stores, forums, or entertainment platforms). If a user signs up for a random website using their Gmail address and the exact same password they use for their email, that credential pair becomes compromised when that specific website is hacked. 2. Credential Stuffing Databases
If you find a "Gmail password list txt" file online, it is a list generated by Google or any legitimate source. These are stolen credentials obtained through several illegal methods: