Nikkei discloses Microsoft and Google account compromises
Nikkei says a Microsoft 365 account sent about 9,000 phishing emails and a July Google breach may have exposed 1,646 people.
Japanese publisher Nikkei disclosed that an attacker accessed an employee Microsoft 365 account and, on September 30, used it to send about 9,000 phishing emails with malicious links. The Record says the messages reached people inside and outside the company, including journalistic sources, while BleepingComputer says they went to staff and interviewees; names, email addresses, and some mailbox contents may have been exposed. Separately, unauthorized access to a Google Workspace account from late July may have exposed data on 1,646 employees and partners: BleepingComputer specifies names and email addresses and says readers and interviewees were not affected, The Record describes the exposure more broadly as personal data, and Infosecurity Magazine includes others. Nikkei reset passwords, warned recipients, reported the incidents to Japan's data protection authority—which Infosecurity identifies as the Personal Information Protection Commission—has not attributed them or said how the accounts were compromised, and says no further unauthorized access was seen. Infosecurity also reports that group unit Nikkei BP disclosed a September 30 phishing-led mailbox compromise affecting 26 contacts. Earlier incidents cited include a 2025 Slack breach that exposed 17,368 people after infostealer-stolen credentials—described by BleepingComputer only as more than 17,000—a 2022 ransomware attack on Nikkei's Singapore subsidiary, and a 2019 business-email-compromise loss of about $29 million.
- On September 30, a compromised Nikkei Microsoft 365 account sent about 9,000 phishing emails with malicious links.
- Sources disagree on recipients: The Record says people inside and outside the company, including journalistic sources; BleepingComputer says staff and interviewees.
- Names, email addresses, and some email or mailbox contents may have been exposed through the Microsoft account.
- Unauthorized Google Workspace access from late July may have exposed data on 1,646 employees and partners; BleepingComputer limits this to names and email addresses and says readers and interviewees were not affected, while The Record says…
- Nikkei reset passwords, warned recipients, reported the incidents to Japan's data protection authority (named by Infosecurity as the Personal Information Protection Commission), has not attributed them or said how access occurred, and…
- Group unit Nikkei BP reported a separate September 30 phishing-led mailbox compromise affecting 26 contacts.
- A 2025 Slack breach tied to infostealer-stolen credentials exposed 17,368 people; earlier incidents include 2022 ransomware at Nikkei's Singapore subsidiary and a 2019 business-email-compromise loss of about $29 million.
Coverage timelineoldest first · each row is one article
- · 3d agoJapanese media group Nikkei discloses cyberattack targeting journalistic sources
The Record· 76
Nikkei says a hijacked Microsoft 365 account sent about 9,000 phishing emails, including to journalistic sources.
- · 3d agoNikkei discloses breaches of employees’ Microsoft, Google email accounts
BleepingComputer· 58
Nikkei says attackers breached Google and Microsoft employee email accounts and sent 9,000 phishing emails.
- · 2d agoNikkei Discloses Two Employee Cloud Account Compromises
Infosecurity Magazine· 63