BreachesMedium

Nikkei says hijacked employee account sent 9,000 phishing emails to contacts and sources

Japan's Nikkei disclosed that an attacker took over an employee's Microsoft 365 account and used it to send roughly 9,000 malicious emails. The Record reports a separate Google Workspace intrusion affected 1,646 people.

Nikkei says hijacked employee account sent 9,000 phishing emails to contacts and sources

At a glance

  • An attacker compromised a Nikkei employee's Microsoft 365 account and sent about 9,000 emails containing links to malicious websites on September 30
  • Nikkei says leaked data is believed to include recipients' names, email addresses and the content of some emails
  • The Record reports a separate, earlier intrusion into Nikkei's Google Workspace affected 1,646 employees and business partners
  • Neither incident has been attributed to a specific group, and Nikkei has not said whether they are connected

Nikkei Inc., the Japanese media group that publishes the Nikkei business daily and owns the Financial Times, has disclosed that an attacker hijacked an employee's Microsoft 365 account and used it to send roughly 9,000 malicious emails to internal and external contacts. In a statement published on October 5, 2026, the company said the compromised account was used on September 30 to distribute messages containing "links to malicious websites," and that it has reported the breach to Japan's Personal Information Protection Commission.

What happened

According to Nikkei's announcement, a third party gained unauthorized access to a Microsoft 365 account belonging to a company employee and used it to send spoofed emails to people who had previously corresponded with Nikkei personnel. The Record reports that the recipients included journalistic sources, and that the intrusion was detected in early September before the mass mailing went out on September 30.

Nikkei said the information exposed "is believed to include recipients' names and email addresses, as well as the content of some emails." The company has not published a final victim count and said an investigation into the scope and number of affected records is ongoing.

A second, earlier intrusion

The Record reports that Nikkei disclosed a second and separate incident at the same time: unauthorized access to the company's Google Workspace environment that began in late July and was discovered in early August after an alert from Google. According to The Record, that intrusion affected 1,646 individuals — employees and business partners — and exposed names and email addresses only, with no reader or source information compromised and no evidence of misuse or subsequent unauthorized logins.

The Record notes that neither incident has been attributed to a specific hacking group and that Nikkei has not confirmed whether the two are connected.

Who is affected

The immediate risk falls on the people who received the September 30 messages, because the mail arrived from a genuine Nikkei mailbox and therefore passed the usual sender checks. Nikkei warned that "there may be an increase in emails impersonating Nikkei employees or our group companies," according to The Record — a signal that the contact data taken from the mailbox may be reused in follow-on social engineering.

That matters more than usual for a news organisation. The Record reports that the recipients included sources, meaning the exposure is not only a privacy issue but a potential source-protection issue for reporters whose correspondence sat in the affected mailbox.

The Record also places the disclosure in context, describing it as Nikkei's third significant incident in recent years, after a 2025 malware-driven breach affecting more than 17,000 users and a ransomware attack on its Singapore operation in 2022.

What to do

Nikkei said it changed the password on the compromised account, contacted recipients individually to ask them to delete the messages, notified the Personal Information Protection Commission, and is strengthening its security and information-management practices. The company added: "We sincerely apologize for the concern and inconvenience caused to all those affected."

Anyone who received an unexpected email from a Nikkei address around September 30 should delete it without opening the links and treat any later message referencing that correspondence with suspicion. For organisations generally, the pattern — one compromised cloud mailbox turned into a trusted mass-phishing channel — argues for phishing-resistant multi-factor authentication on mail accounts and for alerting on sudden high-volume outbound sends from a single user.

Sources

This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.