Nikkei discloses breaches of employees’ Microsoft, Google email accounts

Over the weekend, Japanese publishing giant Nikkei disclosed that unknown attackers recently breached two employee email accounts and used one to send thousands of phishing emails.

In a Sunday statement, the company said an employee’s Google Workspace account was accessed in late July, exposing the personal information of employees and business partners.

Nikkei changed the account’s password after discovering the breach in early August, following a notification from Google.

While this incident may have exposed the names and email addresses of 1,646 individuals, Nikkei says the affected data doesn’t include information about readers or interviewees.

More recently, threat actors accessed another employee’s Microsoft 365 account in September and used it to send 9,000 phishing emails targeting Nikkei staff and interviewees.

“On September 30th , emails containing links to malicious websites were sent to internal staff and to interviewees with whom several employees had been in contact,” the media giant said. “Our company has changed its passwords, and no unauthorized logins have been confirmed since then. We have contacted the recipients individually and requested that they delete the emails.”

The company also warned affected individuals to watch for suspicious emails that may impersonate Nikkei or its subsidiaries in new phishing attacks.

Nikkei has yet to attribute the attacks to a specific threat actor or hacking group and hasn’t shared whether the two incidents are connected.

These are the latest in a string of security incidents Nikkei has disclosed in recent years. Last year, the company also revealed that its Slack messaging platform had been breached, affecting more than 17,000 employees and business partners.

In May 2022, Nikkei’s Singapore subsidiary was hit by a ransomware attack that affected a server “likely” containing customer data. Three years earlier, in late September 2019, Nikkei lost approximately $29 million in a business email compromise (BEC) attack that targeted a Nikkei America employee.

Nikkei owns the Financial Times and The Nikkei, the world’s largest financial newspaper, and is one of the world’s largest media corporations.

It controls more than 40 affiliated companies involved in publishing, broadcasting, events, database services, and the index business, has 37 foreign editorial bureaus and over 1,500 journalists worldwide, and has over 3.7 million digital paid subscriptions.

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

French tax authority data breach affects 678,000 individuals

Hackers stole Pentagon personnel records of over 3 million people

Bitget hacked via zero-day in third-party security products

Bitget resumes Bitcoin withdrawals after $387.5 million crypto heist

Times Car confirms data breach affecting 6.6 million user accounts

Anthropic asks Claude users to share voice data for AI model training

ShinyHunters hacker reportedly detained in Jordan, aiding FBI

Citrix patches NetScaler SAML zero-day exploited in attacks

Free Identity Governance for up to 150 Users: Try Our Community Edition

Your access review passed cleanly, but it never saw the agents swimming under the surface. See how Token Security fishes out every one of them.

Overdue a password health-check? Audit your Active Directory for free

73% of orgs feel prepared for attacks. 82% had a browser incident last year anyway.

Free Identity Governance for up to 150 Users: Try Our Community Edition

Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure

Read our posting guidelinese to learn what content is prohibited.