Nikkei Email Breaches Expose 1,646 People
Nikkei says attackers hit a Google Workspace account in July and a Microsoft 365 account in September, later sending 9,000 phishing emails.
Two employee email accounts at one of the world's largest media companies were accessed by unknown attackers in separate incidents this summer and fall, Nikkei disclosed over the weekend. One of those accounts was then used as a launchpad for a phishing campaign aimed at the publisher's own staff and interview subjects.
The disclosures, issued in a Sunday statement, cover a Google Workspace compromise in late July and a Microsoft 365 compromise in September. Nikkei said it has not yet determined who was behind either intrusion, and it has not said whether the two events are linked.
Google account hit in July
According to the company's account, an employee's Google Workspace account was accessed in late July. That intrusion exposed personal information belonging to employees and business partners. Nikkei changed the account's password in early August after discovering the breach, a step it took following a notification from Google.
The exposed data may have included the names and email addresses of 1,646 individuals. Nikkei stated that the affected information does not include data about readers or interviewees, limiting the scope of that particular exposure to internal and partner contacts.
The company did not describe how the account was initially accessed, nor did it say whether the Google Workspace account was protected by multifactor authentication at the time.
Microsoft 365 account abused in September
The second incident unfolded differently. Threat actors accessed a different employee's Microsoft 365 account in September, and from there used it to send outbound mail. According to Nikkei, the compromised account was used to send 9,000 phishing emails targeting the company's staff and interviewees.
The company did not say how the Microsoft 365 credentials were obtained, or whether the same access method was used in both cases.
Phishing wave on September 30
Nikkei placed the outbound campaign on a specific date.
"On September 30th , emails containing links to malicious websites were sent to internal staff and to interviewees with whom several employees had been in contact," the media giant said. "Our company has changed its passwords, and no unauthorized logins have been confirmed since then. We have contacted the recipients individually and requested that they delete the emails."
— Nikkei, in its Sunday statement
That sequence — access, then mass mailing from a trusted internal address — is the pattern the company described. The messages carried links pointing to malicious websites, sent to people who had reason to expect correspondence from Nikkei employees.
Recipients told to delete messages
Nikkei said it has contacted recipients individually and asked them to delete the emails. It also warned affected individuals to watch for suspicious messages that may impersonate Nikkei or its subsidiaries in follow-on phishing attempts.
The company said no unauthorized logins have been confirmed since it changed passwords. It has not shared further technical indicators, such as the domains used in the phishing links or the sender addresses involved.
Timeline of disclosures
These are the latest entries in a record of security incidents Nikkei has disclosed over several years.
- Late July: An employee's Google Workspace account is accessed.
- Early August: Nikkei discovers the breach after a notification from Google and changes the account password.
- 1,646: Individuals whose names and email addresses may have been exposed in the Google Workspace incident.
- September: Threat actors access a different employee's Microsoft 365 account.
- September 30: Emails with links to malicious websites are sent to internal staff and interviewees.
- 9,000: Phishing emails sent from the compromised Microsoft 365 account.
The company has not attributed either incident to a named threat actor or hacking group.
Prior incidents at the publisher
Last year, Nikkei revealed that its Slack messaging platform had been breached, affecting more than 17,000 employees and business partners.
In May 2022, Nikkei's Singapore subsidiary was hit by a ransomware attack that affected a server "likely" containing customer data. Three years earlier, in late September 2019, Nikkei lost approximately $29 million in a business email compromise attack that targeted a Nikkei America employee.
Those episodes share a common thread with the newest disclosures: email and collaboration accounts as the entry point, and financial or data loss as the downstream effect. The 2019 BEC incident, in particular, turned on a compromised email account rather than a flaw in external-facing infrastructure.
A sprawling target surface
Nikkei owns the Financial Times and The Nikkei, described as the world's largest financial newspaper, and is one of the world's largest media corporations. It controls more than 40 affiliated companies involved in publishing, broadcasting, events, database services, and the index business.
The publisher has 37 foreign editorial bureaus and over 1,500 journalists worldwide, and reports over 3.7 million digital paid subscriptions. That footprint means a compromised employee mailbox can reach a wide array of outside contacts — sources, partners, and colleagues across countries — which is what happened in the September mailing.
What Nikkei has not said
Several questions remain open in the company's disclosure. Nikkei has not identified the attackers, has not said whether the July and September incidents are related, and has not described how the accounts were accessed in either case.
The company also has not indicated whether the affected accounts were protected by phishing-resistant authentication methods, or whether the attackers moved beyond the two mailboxes into other systems. Its statement focuses on password changes, recipient notifications, and the absence of further unauthorized logins.
Those omissions are common in early breach notifications, where companies disclose what is confirmed and hold back investigative detail. They also leave room for the picture to change as Nikkei's review continues.
Why it matters
For security teams, the Nikkei disclosures are a reminder that business email and productivity suites remain among the most valuable footholds an intruder can take. A single mailbox yields contacts, message history, and — as the September campaign shows — an authenticated channel from which to send convincing phishing mail at scale. Defenders looking at their own exposure could reasonably ask whether account takeovers would be detected quickly, whether outbound mail anomalies would trigger alerts, and whether recipients outside the organization would be warned as promptly as Nikkei says it warned its own contacts.
For the broader public, the pattern points to a specific risk that outlasts the initial breach: follow-on messages that impersonate a trusted brand. Nikkei's own warning to watch for emails appearing to come from the company or its subsidiaries is the kind of caution that applies well beyond this incident, since recipients who already received one malicious message remain attractive targets for a second attempt. This story is, for now, based on Nikkei's own account, with no independent confirmation of the scope or attribution — a reminder that early disclosures often raise as many questions as they answer.
Sources
- BleepingComputer Original source
- revealed that its Slack messaging platform had been breached Also reporting
- was hit by a ransomware attack Also reporting
- Nikkei lost approximately $29 million Also reporting
Continue Reading
Italy fines IQVIA $7.8M over health data
Italy's privacy regulator fined IQVIA €7M for pseudonymization failures it says risked re-identifying roughly one million patients.
Small Mistakes, Big Breaches This Week
Citrix and FortiMail zero-days, a new Spectre v2 variant, and a 16-year-old suspect top this week's threat roundup.
Cling Botnet Hides Commands in STUN Traffic
New botnet abuses common STUN protocol and public servers to blend command-and-control with legitimate NAT-traversal activity.