Nikkei Inc., publisher of Japan’s largest financial newspaper, disclosed that attackers compromised employee Microsoft 365 accounts and used them to send roughly 9,000 spoofed emails containing links to malicious websites, the company reported October 4.
The compromised accounts sent the spoofed messages on September 30. Recipients included Nikkei staff as well as numerous external contacts and business partners who had previously corresponded with the affected employees, meaning the malicious emails arrived from addresses the recipients would have recognized and trusted.
Spoofed Emails Likely Exposed Recipient Names and Message Content
Nikkei said the attack is believed to have exposed recipients’ names, email addresses, and the content of some messages. Because the spoofed emails were sent from genuine, previously-used Nikkei employee accounts, external recipients who received the malicious links faced an elevated risk of falling for phishing attempts that appeared to come from a known, trusted source rather than an obvious external attacker.
Nikkei has not confirmed the initial access vector that allowed attackers into the Microsoft 365 accounts in the first place, leaving open how the intrusion began before the mass-email event. The company also has not said how many individual employee accounts were compromised to generate the roughly 9,000 outbound messages, or whether the attackers maintained access to those accounts after the spoofed-email campaign was sent.
A Second, Longer-Running Cloud Service Breach
Separately from the Microsoft 365 compromise, Nikkei disclosed unauthorized access to a different cloud service that has been ongoing since late July — roughly two months before the breach became public. That intrusion potentially exposed the personal information of 1,646 employees and business partners. Nikkei has not said whether the two incidents are connected or carried out by the same actor, and the company has not detailed which cloud service was affected by the longer-running intrusion or what specific categories of personal information beyond general identifying details may have been exposed.
The nearly two-month gap between when the cloud-service intrusion reportedly began and when Nikkei disclosed it illustrates a dwell-time pattern common to many breaches: unauthorized access is often detected well after it starts, during which time the exposed data remains accessible to the intruder without the affected organization’s knowledge.
Nikkei Reports Both Incidents to Japan’s Privacy Regulator
Nikkei reported both the Microsoft 365 compromise and the separate cloud-service breach to Japan’s Personal Information Protection Commission the same day it disclosed the incidents publicly. The company acknowledged a recent rise in cyberattacks against it, though it did not detail the specific frequency or nature of prior incidents beyond that general acknowledgment.
Why Trusted-Sender Phishing Is Especially Effective
Business email compromise campaigns that hijack real employee accounts, rather than spoofing a domain from the outside, represent one of the more effective phishing vectors because they bypass the skepticism recipients typically apply to unfamiliar senders. A message arriving from a known Nikkei contact’s actual account, referencing a prior working relationship, is far more likely to be opened and acted upon than a generic phishing attempt from an unfamiliar address. Security researchers have documented this pattern across numerous business email compromise incidents in recent years: once an attacker gains control of a legitimate account, the trust already established between sender and recipient becomes the attack’s primary weapon.
The scale of this incident — roughly 9,000 messages sent to a mix of internal staff and external partners — also illustrates how a single compromised organization’s email infrastructure can cascade outward, turning one company’s account compromise into a distribution mechanism that reaches well beyond its own employees and into its wider business network.
1,646 Records and 9,000 Recipients Left Exposed
Up to 1,646 employees and business partners potentially had personal information exposed through the separate cloud-service breach, while the broader population of roughly 9,000 spoofed-email recipients faces elevated phishing and malware risk from messages sent under the guise of a trusted Nikkei contact. As a major financial publisher, Nikkei’s compromised communications channel carries particular weight given the volume of business correspondence the company maintains with external partners, sources, and corporate contacts across Japan’s financial sector.
Nikkei has not disclosed whether any recipients of the spoofed emails clicked the malicious links or suffered further compromise as a result, nor has it provided a timeline for resolving the unauthorized cloud access that began in late July. With both incidents now in front of Japan’s Personal Information Protection Commission, further detail on the investigation’s findings and any resulting regulatory response may follow as the review proceeds.
