Nikkei email account breaches led to 9,000 phishing emails
Japanese media group Nikkei has disclosed that unknown attackers breached two employee email accounts, one on Google Workspace and one on Microsoft 365, and used the second to send about 9,000 phishing emails, according to BleepingComputer’s report of the company’s statement. The attackers have not been identified, and Nikkei has not said whether the two incidents are linked.
What we know about the Nikkei email breach
Per the report, Nikkei published its statement over the weekend. It describes two separate account compromises:
- Google Workspace, late July: an employee’s account was accessed. Nikkei changed the password after Google notified it in early August.
- Microsoft 365, September: another employee’s account was accessed and used to send roughly 9,000 phishing emails to Nikkei staff and to interviewees that employees had been in contact with.
Nikkei says the malicious emails, containing links to malicious websites, went out on September 30. The company reports it has reset passwords, has not confirmed any unauthorised logins since, and has contacted recipients individually to ask them to delete the messages.
Who is affected
The Google Workspace incident may have exposed the names and email addresses of 1,646 employees and business partners. Nikkei says the affected data does not include information about readers or interviewees.
The phishing wave targeted internal staff and interviewees, people who would reasonably trust a message from a Nikkei employee. Nikkei has also warned affected individuals to watch for further phishing that impersonates Nikkei or its subsidiaries.
What has not been confirmed
- Who is behind either intrusion: Nikkei has not attributed the attacks to any threat actor.
- Whether the July and September incidents are connected: not disclosed.
- How the accounts were compromised: not disclosed in the source.
- What the malicious links led to, such as credential harvesting or malware: not disclosed.
Why this matters
This section is our analysis, not new reporting.
Phishing sent from a real, compromised internal mailbox is harder to filter than spoofed mail. It passes SPF, DKIM and DMARC because it genuinely originates from the organisation’s tenant, and recipients tend to trust it. Any organisation that exchanges mail with a company in this position should treat messages from it with extra caution for a while.
The timeline is also a reminder of detection lag. Per the report, the Google account was accessed in late July and the breach was found in early August after a notification from Google, a gap of days to weeks. A Nikkei-style incident is a useful test of whether your own team would notice a quiet mailbox takeover.
The company has disclosed several earlier incidents, including a Slack breach affecting more than 17,000 people last year, a 2022 ransomware attack on its Singapore subsidiary, and a roughly $29 million business email compromise loss in 2019, according to the same report. Repeated incidents suggest identity and email access are recurring weak points, though the source does not say the cases share a cause.
What to do
- If you received a Nikkei-branded email recently: do not click links, delete it, and report it to your security team. Treat any unexpected message referencing a Nikkei interview or contact with suspicion.
- Hunt for the pattern in your own mail logs: look for messages from Nikkei domains around September 30 that contain links, and check whether any user clicked.
- If a user clicked: reset the password, revoke active sessions and tokens, and review mailbox rules and OAuth app grants for new forwarding or consent entries.
- Review sign-in logs for your own tenants: check Microsoft 365 and Google Workspace for unusual logins, new devices, and sudden spikes in outbound mail from a single user.
- Enforce phishing-resistant MFA: hardware keys or passkeys for staff, especially those who deal with external contacts such as press, sales and support.
- Set outbound mail alerts: flag accounts that send thousands of messages in a short period, which is how a compromise like this surfaces quickly.
- Brief staff and partners: remind them that mail from a known sender can still be malicious if that sender’s account is compromised.
