Security News

Nikkei Hit by Two Cloud Account Compromises, With 9000 Phishing Emails Sent from a Staff Account

Infosecurity Magazine · 7 Oct 2026
Key Takeaway Treat any unexpected email from a known contact with caution, since a compromised staff account can send convincing phishing to colleagues and customers, and make sure you can quickly reset passwords and warn recipients if it happens.

Japanese media group Nikkei has disclosed unauthorised access to two employee cloud accounts. In the first case, an employee's Google Workspace account was accessed from outside from late July, potentially exposing the names and email addresses of 1646 employees, business partners and others. Nikkei learned of it in early August after a notification from Google and changed the password immediately. It has seen no further unauthorised logins and has not confirmed any secondary harm.

In the second case, an employee's Microsoft 365 account was compromised and used on September 30 to send around 9000 emails directing recipients to malicious websites. The emails went to colleagues and to news sources and other contacts of several employees. Recipient names, email addresses and the content of some emails may have been exposed. Nikkei changed the password, contacted recipients individually to ask them to delete the messages, and warned that more suspicious emails posing as Nikkei or its group companies may follow. The investigation is continuing. Nikkei has not said how either account was compromised, who was behind the activity, or whether the two incidents are connected.

Separately, group publisher Nikkei BP said an employee's email account was accessed on September 30 after credentials were stolen through a phishing email sent from a Nikkei employee's address, potentially exposing 26 names and email addresses. The disclosures follow a November 2025 breach in which credentials stolen by infostealer malware on an employee's personal computer were used to access Nikkei's Slack workspace.

phishing Microsoft 365 Google Workspace account compromise

Summarised by CISO AI from Infosecurity Magazine, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.