Skip to main content
Emerging ThreatsData Breaches

Nikkei Exposes Employee Cloud Account Breaches

Employees work at desks in a brightly-lit office with a computer screen showing a cloud service login page.

Around 9,000 phishing emails were sent from a hijacked Microsoft 365 mailbox on September 30, Nikkei disclosed on October 4, in the latest in a string of account compromises that the company says exposed employee and partner contact data.

Google Workspace account accessed from late July

Nikkei said an employee's Google Workspace account had been accessed from outside since late July and that the company learned of the access in early August after receiving a notification from Google. The company immediately changed the account password and, as of its October 4 statement, reported no further unauthorized logins and no confirmed secondary harm. Nikkei said the exposed information included names and email addresses for 1,646 employees, business partners and others, but did not include details of readers or news sources. The incident has been reported to Japan's Personal Information Protection Commission.

Microsoft 365 mailbox used to send roughly 9,000 phishing messages

In a separate disclosure the same day, Nikkei reported that an employee's Microsoft 365 account was compromised and used on September 30 to send approximately 9,000 emails directing recipients to malicious websites. Those messages were sent both within the company and to news sources and other external contacts of several employees. Nikkei said recipients' names and email addresses — and the content of some emails — may have been exposed in that incident. The company changed the account password, has detected no further unauthorized logins, and said it contacted recipients individually to ask them to delete the malicious messages. Nikkei warned that more suspicious messages posing as Nikkei or its group companies may follow, and it has reported the Microsoft 365 incident to the regulator and is continuing its investigation.

Nikkei BP incident and a recurring pattern of credential theft

Also on October 4, group publisher Nikkei BP disclosed that an employee's email account was accessed on September 30 after their credentials were stolen through a phishing email that had been sent from a Nikkei employee's address. That exposure potentially affected 26 names and email addresses. Nikkei's latest disclosures follow a November 2025 breach the company reported, in which credentials stolen by infostealer malware on an employee's personal computer were used to access its Slack workspace and expose data on 17,368 people. Nikkei also reminded readers that in 2019 Nikkei America lost about $29m in a business email compromise scam.

What this means for technologists, regulators, and news sources

  • Technologists and security teams: Nikkei changed affected passwords and says it has detected no further unauthorized logins; teams will be focused on the ongoing investigation into the Microsoft 365 incident, post-incident monitoring for additional suspicious messages, and the company's stated plans to tighten handling of personal information and defenses against unauthorized access.
  • Policymakers and regulators: The company has reported the incidents to Japan's Personal Information Protection Commission, putting the regulator in a position to receive the company's findings as its internal investigation proceeds.
  • News sources and contacts of Nikkei employees: Recipients were contacted individually and asked to delete the phishing messages; Nikkei has warned they may see further suspicious messages purporting to come from Nikkei or its group companies.

Nikkei's stated next steps and remaining factual gaps

Nikkei said it will tighten its handling of personal information and its defenses against unauthorized access. The company has not said how either of the two most recent employee accounts was compromised, who was behind the activity, or whether the Google Workspace and Microsoft 365 incidents are connected. Those are open elements of the company's ongoing investigation and are the specific gaps the regulator and affected parties will be watching as Nikkei follows through on remediation.

The sequence of recent incidents — a Google Workspace compromise traced to unauthorized access beginning in late July, a mass-phishing event from a Microsoft 365 account on September 30, a Nikkei BP email access tied to credential theft the same day, and prior breaches in November 2025 and 2019 — forms a factual record of repeated credential and mailbox abuse that the company says it is addressing through password resets, recipient notifications and promises to strengthen controls.

Source: https://www.infosecurity-magazine.com/news/nikkei-employee-cloud-account/