Nikkei Discloses Microsoft 365 and Google Workspace Account Breaches

Nikkei says attackers breached two employee email accounts, exposed data on 1,646 people and sent about 9,000 phishing emails from a Microsoft 365 account.
Table of Contents
    Add a header to begin generating the table of contents

    Japanese publisher Nikkei disclosed that unknown attackers breached two employee email accounts, one on Google Workspace and one on Microsoft 365, exposing personal details of 1,646 people and using the Microsoft account to send about 9,000 phishing emails to internal staff and interviewees. The company issued its statement on Sunday, October 4, and the incidents were reported on October 6.

    Microsoft 365 Account Used to Send 9,000 Phishing Emails on September 30

    Nikkei said attackers accessed an employee’s Microsoft 365 account in September. On September 30 they used it to send roughly 9,000 emails containing malicious links to internal staff and to people the company had interviewed. The messages came from a real Nikkei account, which gave recipients reason to trust them.

    The timeline runs from the late-July Google Workspace access, to early-August discovery, to the September Microsoft 365 access and the September 30 phishing run. The company has contacted recipients individually and asked them to delete the emails. It has also warned of impersonation phishing, in which messages appear to come from Nikkei staff. Interviewees are a particular concern for a news organization, since they include people who spoke to journalists, sometimes in confidence.

    Nikkei Password Resets After the Microsoft 365 Phishing Wave

    Nikkei changed the passwords on the affected accounts, and the company says there have been no unauthorized logins since. It did not name the attackers and did not say whether the two incidents are linked.

    Google Workspace Account Compromised in Late July Went Unnoticed Until August

    The second incident began in late July, when attackers accessed a Google Workspace account belonging to another employee. The exposed information covers names and email addresses for 1,646 individuals, including employees and business partners. Nikkei said no reader data or interviewee data was involved.

    The company found the intrusion in early August after Google sent a notification, and it changed the account’s password. Google’s notification, not Nikkei’s own monitoring, led to the discovery, and the account had been accessed since late July.

    Nikkei’s Earlier Incidents: Slack, Singapore Ransomware and a $29 Million BEC Loss

    The disclosure follows a series of earlier security problems at the company. Last year, a Slack breach affected more than 17,000 people. In 2022, a Singapore subsidiary suffered a ransomware attack. In 2019, a business email compromise scam cost Nikkei about $29 million.

    Those prior events concern different systems and methods, and nothing in the disclosure ties them to the current compromises. They do show that email and collaboration accounts have been a recurring point of exposure for the publisher.

    Interviewees Among the 9,000 Phishing Recipients

    Attackers who control a mailbox can send trusted-looking messages, as happened here. Nikkei has not said what the mailboxes contained beyond the names and email addresses of 1,646 people.

    Nikkei’s statement said it found no evidence of reader or interviewee data being taken from the Google Workspace account, though interviewees were among the recipients of the September 30 phishing emails. Whether anyone who received one of the messages clicked a link has not been disclosed, and the company has not said what the malicious links led to or whether any credentials were captured.

    Nikkei is the Japanese publisher that owns the Financial Times, which raises the profile of any compromise of its staff and contacts. The company’s statement concentrated on the two accounts and the people who received the messages, and it described no wider network intrusion.

    The absence of attribution leaves the motive unclear. The two intrusions occurred about two months apart and used different platforms, and without further disclosure it is not possible to say whether one group ran both operations or two separate actors targeted two separate employees.

    Related Posts