The Japanese media group said on October 4 that a third party was believed to have logged into an employee’s Microsoft 365 account. On September 30, messages from the account were sent inside the company and to people who had communicated with several Nikkei employees, directing recipients to malicious websites.
Nikkei said recipients’ names and email addresses, as well as the contents of some emails, may have been exposed. The company changed the account password and said it had detected no further unauthorised logins after taking that step.
The company is contacting recipients individually and asking them to delete the messages. It has also warned that suspicious emails impersonating Nikkei or other companies in the group could follow, and urged recipients to remain alert rather than opening links in questionable messages.
Nikkei reported the incident to Japan’s Personal Information Protection Commission and said it was continuing to investigate the extent of the exposure. It has not identified who was responsible, explained how the Microsoft 365 credentials were obtained or established publicly whether the attack was connected to the second account compromise.
That separate incident involved an employee’s Google Workspace account, which Nikkei said had been accessed from outside the company from late July. The intrusion may have exposed names, email addresses and other personal information relating to 1,646 employees, business partners and other people.
Nikkei learned of the Google Workspace access in early August after receiving a notification from Google. It changed the affected account’s password and said no further unauthorised logins had been confirmed afterwards. The company also said it had found no secondary damage arising from that incident.
The potentially exposed Google Workspace information did not include data concerning Nikkei readers or journalistic sources, according to the company. That incident was also reported to the Personal Information Protection Commission.
The disclosures underline the risks created when attackers obtain access to legitimate corporate cloud accounts. In the Microsoft 365 case, the messages were sent from an authentic employee account to people who already had relationships with Nikkei staff, allowing the phishing attempt to exploit an established channel of communication rather than relying solely on a forged sender identity.
The company has not said that all 9,000 messages resulted in compromised recipients. The figure refers to emails sent from the hijacked account, while the number of people whose data may have been exposed through that mailbox remains under investigation. Nikkei has not announced downstream harm from messages.
A related incident at group publisher Nikkei BP showed how such attacks can spread through trusted contacts. Nikkei BP said separately that an employee email account was accessed without authorisation on September 30 after credentials were stolen through a phishing message sent from a Nikkei employee’s address. Names and email addresses contained in 26 records may have been exposed.
Nikkei BP blocked access to the affected account after detecting the compromise and took measures to contain it. The incident was disclosed on the same day as the two Nikkei account breaches, although it was treated separately from the company’s Google Workspace disclosure.
The latest cases add to earlier account-security incidents disclosed by the group. Nikkei said in November 2025 that credentials stolen after malware infected an employee’s personal computer had been used to gain unauthorised access to its Slack environment. Information involving 17,368 people, including names, email addresses and some chat history, was potentially exposed.
Nikkei America also disclosed in May that an employee Microsoft 365 account had been accessed without authorisation earlier in 2026. Impersonation emails were sent to business contacts, while information concerning 291 people, including names, company names and email addresses, may have been exposed.
Follow Arabian Post
Select Arabian Post as your preferred source on Google and MSN News for trusted business news and Arab politics and updates.