Security News

Nikkei Email Account Hijacked to Send 9,000 Phishing Messages to Staff and Journalistic Sources

The Record · 5 Oct 2026
Key Takeaway Turn on multi-factor authentication for every Microsoft 365 and Google Workspace account, and tell staff and contacts to be wary of unexpected links, even from people they know.

Japanese media group Nikkei has disclosed two cyber incidents involving employee email accounts. In the more recent one, an attacker took over a Microsoft 365 account belonging to an employee and used it to send roughly 9,000 phishing emails on September 30. The messages went to people inside and outside the company, including journalistic sources, and contained links to malicious websites. Nikkei said the targets were people who had previously communicated with its employees.

Nikkei changed the account password and has detected no further unauthorized access. It contacted recipients and asked them to delete the messages. Names, email addresses and the contents of some emails may have been exposed. The company reported the incident to Japan's data protection authority and is still working out how many people were affected. It also warned that emails impersonating Nikkei employees or group companies may increase.

Earlier the same day, Nikkei disclosed that a Google Workspace account had been accessed without authorization from late July, potentially exposing personal information of 1,646 people, including employees and business partners. Google alerted the company in early August. Nikkei said the data may have included names and email addresses, but not information about readers or journalistic sources. It has found no evidence of misuse. The company has not said whether the two incidents are linked, and neither has been attributed to a specific hacking group.

phishing Microsoft 365 Google Workspace account compromise data breach

Summarised by CISO AI from The Record, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.