Nikkei discloses breaches of employees’ Microsoft, Google email accounts
Description
Japanese media giant Nikkei disclosed breaches of two employee email accounts—one Google Workspace account accessed in July and one Microsoft 365 account accessed in September. The Google account breach exposed personal information of 1,646 employees and business partners but did not include reader or interviewee data. The Microsoft 365 breach was used to send 9,000 phishing emails targeting internal staff and interviewees. Nikkei changed passwords after discovering the breaches and has contacted affected individuals. No unauthorized logins have been detected since remediation. The company has not attributed the attacks to any specific threat actor or linked the two incidents.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Nikkei experienced two separate email account breaches involving employee accounts on Google Workspace and Microsoft 365. The first breach, detected in early August, involved unauthorized access to a Google Workspace account in late July, exposing personal information of employees and business partners. The second breach occurred in September when attackers accessed a Microsoft 365 account and sent thousands of phishing emails internally and to interviewees. Nikkei responded by changing passwords and notifying affected parties. The company has not confirmed any ongoing unauthorized access or linked the two breaches. These incidents follow previous security events at Nikkei, including a Slack breach, ransomware attack, and a business email compromise.
Potential Impact
The breaches exposed personal information of 1,646 employees and business partners and facilitated a large-scale phishing campaign targeting Nikkei staff and interviewees. The phishing emails contained links to malicious websites, potentially increasing the risk of credential theft or malware infections among recipients. There is no indication that reader or interviewee data was compromised beyond email contact information. No further unauthorized access has been detected since remediation steps were taken.
Defensive Guidance
Nikkei has changed the passwords of the compromised accounts and contacted affected individuals to delete phishing emails. No unauthorized logins have been confirmed since these actions. Affected individuals are advised to remain vigilant for suspicious emails impersonating Nikkei or its subsidiaries. Organizations should ensure strong password policies and multi-factor authentication are in place for email accounts to reduce the risk of similar breaches.
Technical Details
- Classification
- {"confidence":0.65,"severitySource":"default","classifier":"rss-v2"}
Threat ID: 6ac4c06b2cdf04f65693dbe3
Added to database: 10/06/2026, 09:33:31 UTC
Last enriched: 10/06/2026, 09:33:36 UTC
Last updated: 10/06/2026, 15:33:31 UTC
Views: 22
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.