Japanese media company Nikkei has disclosed two separate cyber incidents involving employee accounts on Microsoft 365 and Google Workspace. One of the incidents allowed attackers to use an employee's account to send about 9,000 phishing emails, while the other may have exposed the personal information of 1,646 employees and business partners.
The incidents were disclosed on October 4 and reveal the risks organizations face when attackers gain access to legitimate employee accounts. Nikkei has not attributed either incident to a specific hacking group or confirmed whether the two attacks were connected.
Microsoft 365 account used to send phishing mails
The more recent incident involved an employee's Microsoft 365 account. According to Nikkei, attackers gained unauthorized access to the account and used it on September 30 to send approximately 9,000 emails.
The messages were sent to people both inside and outside the company. Some recipients were journalistic sources and other individuals who had previously communicated with Nikkei employees.
The emails contained links leading to malicious websites. Because the messages were sent from a legitimate Nikkei employee account, recipients could have been more likely to trust them. This type of account compromise can allow attackers to use an organization's existing relationships to distribute phishing messages.
Nikkei said the incident may have exposed recipients' names and email addresses, along with the contents of some emails. The company is still investigating the number of people whose personal information may have been affected. According to Nikkei, “There may be an increase in emails impersonating Nikkei employees or our group companies,”
Google workspace breach
Nikkei also disclosed a separate incident involving an employee's Google Workspace account. The account was accessed without authorization beginning in late July.
The company discovered the intrusion in early August after receiving an alert from Google. Nikkei then changed the account's password and said it has not detected any further unauthorized access.
The incident may have exposed information belonging to 1,646 employees and business partners. The potentially affected information included names and email addresses.
Nikkei said the exposed information did not include data related to its readers or journalistic sources. The company also said it has found no evidence that the information was misused.
Nikkei’s response
After the Microsoft 365 incident, Nikkei changed the affected password and contacted recipients of the phishing emails, asking them to delete the messages. The company warned that additional emails impersonating Nikkei employees or its group companies could appear.
Nikkei has also reported the incidents to Japan's data protection authority. Investigations into the scope of the Microsoft 365 compromise and the information potentially exposed are continuing.
Nikkei has experienced other cybersecurity incidents in recent years. In November 2025, the company disclosed a malware-related credential theft incident that potentially exposed information connected to more than 17,000 employees and business partners.
Read the original article:
