Skip to main content
Emerging ThreatsData Breaches

Nikkei Breaches Email Accounts, Exposes Data

Employees work at desks in a bright office with a city view, one with a laptop and papers nearby.

"On September 30th , emails containing links to malicious websites were sent to internal staff and to interviewees with whom several employees had been in contact," the media giant said.

Over the past three months Nikkei acknowledged two separate breaches of employee email accounts that exposed personal contact information and were later used to distribute phishing. One incident involved a Google Workspace account accessed in late July; the other involved a Microsoft 365 account in September that was used to send roughly 9,000 phishing emails to Nikkei staff and people the company had interviewed.

Google Workspace account accessed in late July

According to Nikkei's Sunday statement, an employee's Google Workspace account was accessed in late July. The company said the intrusion exposed the personal information of employees and business partners. Nikkei estimated that names and email addresses for 1,646 individuals may have been exposed, and clarified that the affected data "doesn't include information about readers or interviewees."

Nikkei said it changed the account's password after discovering the breach in early August, following a notification from Google.

Microsoft 365 account used to send 9,000 phishing emails

Nikkei reported a second compromise in September: "threat actors accessed another employee's Microsoft 365 account" and used it to send about 9,000 phishing messages targeting Nikkei staff and interviewees. The company said the messages "contained links to malicious websites" and that those messages were sent on September 30th.

In response, Nikkei changed passwords and said "no unauthorized logins have been confirmed since then." The company also said it has contacted recipients individually and requested that they delete the suspicious emails, and warned affected individuals to watch for emails that may impersonate Nikkei or its subsidiaries in further phishing attempts.

Nikkei has not attributed the attacks or linked the two incidents

As of its disclosure, Nikkei has not attributed either intrusion to a named threat actor or hacking group, and has not shared whether the two incidents are connected. The company limited its public detail to the account types affected, the timing, the numbers of potentially exposed contacts, and the remedial steps it took (password changes, recipient notifications, and deletion requests).

Nikkei's recent security incident history and corporate footprint

These incidents are the latest the company has disclosed in recent years. Nikkei said last year that its Slack messaging platform had been breached, affecting more than 17,000 employees and business partners. In May 2022 its Singapore subsidiary suffered a ransomware attack that affected a server "likely" containing customer data. In late September 2019 Nikkei reported losing approximately $29 million in a business email compromise attack that targeted a Nikkei America employee.

The disclosures come from one of the world's largest media corporations: Nikkei owns the Financial Times and The Nikkei, operates more than 40 affiliated companies across publishing, broadcasting, events, database services and index businesses, maintains 37 foreign editorial bureaus, employs over 1,500 journalists worldwide, and reports more than 3.7 million digital paid subscriptions.

What this means for Nikkei staff, interviewees, and business partners

  • Nikkei staff: Employees were directly targeted by phishing sent from a compromised Microsoft 365 account; the company reported changing passwords and said it found no further unauthorized logins after its remediation.
  • Interviewees: Nikkei said interviewees received some of the phishing emails; the company has contacted those recipients individually and asked them to delete the messages.
  • Business partners and named contacts: The Google Workspace breach may have exposed the names and email addresses of 1,646 employees and business partners, although Nikkei emphasized the data did not include readers or interviewees.

Nikkei's public account details specific timestamps, affected account types, and the numbers of potentially exposed contacts, and it describes immediate remediation steps taken. It stops short, however, of naming an adversary, declaring a connection between the incidents, or describing additional investigative results. The concrete next steps documented in the disclosure were password changes and individualized outreach to recipients of the phishing messages.

https://www.bleepingcomputer.com/news/security/nikkei-discloses-breaches-of-employees-microsoft-google-email-accounts/