Protect.Computer
NEWS

Nikkei Hijacked Account Sent 9,000 Phishing Emails

· 1 min read · Got hacked Digital scams
Nikkei Hijacked Account Sent 9,000 Phishing Emails

Japanese media group Nikkei disclosed two incidents involving employee email accounts on Sunday. In the first, attackers took over a Microsoft 365 account belonging to an employee and on September 30 used it to send roughly 9,000 phishing emails to people inside and outside the company, including journalistic sources. The messages carried links to malicious websites and targeted people who had previously communicated with Nikkei employees. Nikkei says it changed the account password, has seen no further unauthorized access, and has asked recipients to delete the messages. Names, email addresses and the contents of some emails may have been exposed, the company has reported the incident to Japan’s data protection authority, and it is still working out how many people are affected.

In the second incident, a Google Workspace account used by another employee was accessed without authorization starting in late July, potentially exposing personal information of 1,646 employees and business partners. Nikkei found the intrusion in early August after an alert from Google and says the data did not include information on readers or journalistic sources. Nikkei has not said whether the two incidents are connected, and neither has been attributed to a specific group. The company warned that emails impersonating Nikkei employees or group companies may increase, which is a good reason for anyone who corresponds with Nikkei staff to treat unexpected links from those addresses with suspicion. Nikkei has had earlier incidents, including a November 2025 Slack breach that followed stolen employee credentials.

Sources

Related reading