Japanese media group Nikkei revealed that two employee cloud accounts were accessed without authorization, with one of these accounts subsequently used to send approximately 9,000 phishing emails to staff and external contacts, according to a recent report by Infosecurity Magazine.
The first incident involved a Google Workspace account, compromised since late July, potentially exposing the names and email addresses of 1,646 employees and business partners. Nikkei was alerted by Google in early August and has since secured the account. The second, more recent compromise on Sept. 30, affected a Microsoft 365 account. This account was used to send about 9,000 emails to internal staff and external contacts, directing them to malicious websites. Names, email addresses, and potentially email content may have been exposed in this second incident. Nikkei reported both incidents to Japan's Personal Information Protection Commission and is investigating the exact cause and any potential links between the two breaches. The company stated it saw no further unauthorized logins and has not confirmed any secondary harm, though it warned that more suspicious messages might follow. This follows previous security incidents, including a 2025 breach involving stolen credentials and a significant business email compromise scam in 2019.
Source: Infosecurity Magazine

