Nikkei Email Account Hijacked to Send 9,000 Phishing Messages to Staff and Journalistic Sources
Japanese media group Nikkei has disclosed two cyber incidents involving employee email accounts. In the more recent one, an attacker took over a Microsoft 365 account belonging to an employee and used it to send roughly 9,000 phishing emails on September 30. The messages went to people inside and outside the company, including journalistic sources, and contained links to malicious websites. Nikkei said the targets were people who had previously communicated with its employees.
Nikkei changed the account password and has detected no further unauthorized access. It contacted recipients and asked them to delete the messages. Names, email addresses and the contents of some emails may have been exposed. The company reported the incident to Japan's data protection authority and is still working out how many people were affected. It also warned that emails impersonating Nikkei employees or group companies may increase.
Earlier the same day, Nikkei disclosed that a Google Workspace account had been accessed without authorization from late July, potentially exposing personal information of 1,646 people, including employees and business partners. Google alerted the company in early August. Nikkei said the data may have included names and email addresses, but not information about readers or journalistic sources. It has found no evidence of misuse. The company has not said whether the two incidents are linked, and neither has been attributed to a specific hacking group.