Nikkei Discloses Two Employee Cloud Account Compromises
Nikkei says two employee cloud accounts were hijacked, exposing contacts and sending about 9,000 phishing emails.
Japanese publisher Nikkei disclosed that an employee Google Workspace account was accessed externally from late July, potentially exposing names and email addresses of 1,646 employees, partners, and others. A separate Microsoft 365 account was used on September 30 to send about 9,000 emails directing recipients to malicious sites, and some mailbox content may have been exposed. Nikkei reset both passwords, reported the cases to Japan’s Personal Information Protection Commission, and has not said how the accounts were compromised. Group unit Nikkei BP also reported a September 30 phishing-led mailbox compromise affecting 26 contacts, after a 2025 Slack breach tied to infostealer-stolen credentials exposed 17,368 people.
- Google Workspace access since late July exposed 1,646 contacts.
- A Microsoft 365 account sent about 9,000 phishing emails on September 30.
- Nikkei has not identified the intruder or access method.
- Nikkei BP reported a related phishing compromise affecting 26 contacts.
- A 2025 Slack breach exposed data on 17,368 people.
Full article408 words · extracted from infosecurity-magazine.com · click to collapse
Japanese media group Nikkei has disclosed unauthorized access to two employee cloud accounts, one of which was used to send around 9000 phishing emails to staff and to people its journalists had been in contact with.
In a statement published October 4, the company said an employee's Google Workspace account had been accessed from outside since late July, potentially exposing the names and email addresses of 1646 employees, business partners and others.
Nikkei learned of the access in early August through a notification from Google and changed the account's password immediately. It said it has seen no further unauthorized logins and has not confirmed any secondary harm.
The exposed information does not include details of readers or news sources, Nikkei said. It has reported the incident to Japan's Personal Information Protection Commission.
In a second disclosure the same day, Nikkei said an employee's Microsoft 365 account had been compromised and used on September 30 to send around 9000 emails directing recipients to malicious websites, both inside the company and to news sources and other contacts of several employees.
Hijacked Mailbox Used for Phishing
Nikkei said the recipients' names and email addresses, along with the content of some emails, may also have been exposed in the Microsoft 365 incident, which it has reported to the regulator and is still investigating.
The company changed the account's password, has detected no further unauthorized logins and contacted recipients individually to ask them to delete the emails. It warned that more suspicious messages posing as Nikkei or its group companies may follow.
Nikkei has not said how either of its own accounts was compromised, who was behind the activity or whether the two incidents are connected.
A Wider Pattern of Account Breaches
Group publisher Nikkei BP said separately on October 4 that an employee's email account was accessed on September 30 after their credentials were stolen through a phishing email sent from a Nikkei employee's address, potentially exposing 26 names and email addresses.
The disclosures follow a breach Nikkei reported in November 2025, when credentials stolen by infostealer malware on an employee's personal computer were used to access its Slack workspace, exposing data on 17,368 people. In 2019, Nikkei America lost about $29m in a business email compromise scam.
Nikkei said it will tighten its handling of personal information and its defenses against unauthorized access.