Nikkei breach: hijacked account sent 9,000 phishing emails

Nikkei breach: hijacked account sent 9,000 phishing emails

Japanese media group Nikkei has disclosed two separate security incidents involving employee email accounts. In the more serious one, an attacker took over a staff member's Microsoft 365 account and used it to send phishing emails to journalistic sources.

The company announced both incidents on Sunday. Several other large Japanese companies have reported breaches in recent weeks.

Around 9,000 phishing emails from a trusted address

In the latest incident, the attacker gained access to the Microsoft 365 account of a Nikkei employee. Microsoft 365 is the cloud-based office and email suite that many organizations use. From that account, the attacker sent about 9,000 phishing emails on September 30.

The messages went to people both inside and outside the company. According to Nikkei, the recipients were people who had been in contact with Nikkei employees before, and some of them were journalistic sources. The emails contained links that led to malicious websites.

Nikkei said it has changed the password on the affected account and has not seen any further unauthorized access. It has also contacted the recipients and asked them to delete the messages.

The company believes the incident may have exposed recipients' names and email addresses, along with the contents of some emails. It has reported the breach to Japan's data protection authority. Nikkei has not yet determined how many people had personal information exposed.

The company also warned of possible follow-up attacks: "There may be an increase in emails impersonating Nikkei employees or our group companies."

A second intrusion via Google Workspace

Earlier the same day, Nikkei disclosed an unrelated-looking intrusion into a Google Workspace account belonging to a different employee. Someone had been accessing the account without authorization since late July.

Nikkei found out in early August after Google sent an alert, and the password was changed. The company says personal information of 1,646 people, including employees and business partners, may have been exposed. The data may have included names and email addresses.

According to Nikkei, no information about its readers or journalistic sources was involved. It has seen no further unauthorized logins and no evidence that the exposed data has been misused.

Nikkei has not said whether the Google Workspace and Microsoft 365 incidents are connected. Neither has been attributed to a specific threat actor.

Not Nikkei's first breach

Nikkei is one of the largest business media companies in the world. It publishes the financial newspaper The Nikkei, owns the Financial Times, employs more than 3,000 people and runs dozens of editorial bureaus abroad.

The company has been hit before. In November 2025, it said malware on an employee's computer had stolen credentials that were later used to access Nikkei's internal Slack workspace. That breach potentially exposed names, email addresses and chat histories of more than 17,000 employees and business partners. Nikkei said at the time it had found no sign that information on journalistic sources or reporting had been compromised.

In 2022, ransomware hit the company's Singapore headquarters. Nikkei said that incident may have involved customer data.

A wider wave in Japan

The Nikkei disclosures add to a growing list of incidents at Japanese companies.

Daiwa Securities, the country's second-largest brokerage, said on Monday that data on up to 110,000 customers may have been stolen after attackers breached servers run by an outside vendor. Daiwa said its own systems were not affected and that the exposed data could not, on its own, be used to log in to accounts or place trades.

Delivery company Yamato Transport recently reported unauthorized access to a payment service used for e-commerce purchases. Insurer Dai-ichi Life, delivery firm Sagawa Express and broadcast equipment maker Ikegami Tsushinki have also reported cyber incidents.

Why It Matters

The Microsoft 365 incident shows why a hijacked mailbox can be so useful to an attacker. Emails sent from a real Nikkei account, to people who had already corresponded with Nikkei staff, are far more convincing than cold phishing. When the recipients include journalistic sources, the risk goes beyond credential theft. Sources may have good reasons to keep their contact with a newsroom private, and a breach that touches them is sensitive for any media organization.

The incident fits a wider pattern of attackers abusing trusted accounts rather than building fake ones. A recent example was the hijacked Microsoft X account used to promote a crypto token. Nikkei's own history also points to identity as a recurring weak spot. The 2025 Slack breach started with stolen credentials, and both new incidents involve account takeovers on major cloud platforms. Password resets alone may not be enough if the initial access method, such as infostealer malware or a phishing kit capable of bypassing MFA, is still unknown.

For readers, the immediate takeaway is practical. Anyone who has corresponded with Nikkei staff should treat unexpected links from them with caution for some time, as the company itself warns of more impersonation attempts. Organizations whose staff deal with confidential contacts may want to review how they monitor for unusual bulk sending from internal accounts.

Several things are worth watching. Will Nikkei say how the accounts were compromised, or whether the two incidents are linked? How many people were affected by the phishing wave? And could the cluster of Japanese breaches, from Daiwa's vendor incident to the delivery and insurance firms, be connected, or does it simply show that many organizations share the same gaps?