NEWS

Nikkei Discloses Breaches of Employee Microsoft 365, Google Workspace Accounts

Japanese publisher Nikkei disclosed breaches of two employee email accounts, one used to send roughly 9,000 phishing emails to staff and sources.

Dylan H.

News Desk

October 6, 2026
6 min read
Nikkei Discloses Breaches of Employee Microsoft 365, Google Workspace Accounts

Japanese Media Giant Discloses Dual Email Account Breaches

Over the weekend, Nikkei Inc., the Japanese publishing conglomerate behind the Nikkei business daily and Nikkei Asia, disclosed that unknown attackers recently breached two separate employee email accounts — one on Google Workspace and one on Microsoft 365 — and used the Microsoft 365 account to send approximately 9,000 phishing emails to Nikkei staff and people interviewed by its journalists. The company said the two incidents do not appear to be connected and that no reader or interviewee data was exposed in the earlier of the two breaches.


Incident Details

AttributeValue
OrganizationNikkei Inc.
DisclosedOctober 4–5, 2026 (Japan); October 6, 2026 (English)
Accounts compromised1 Google Workspace account, 1 Microsoft 365 account
Google Workspace breach windowLate July 2026 – discovered early August 2026
Microsoft 365 phishing blastSeptember 30, 2026
Phishing emails sentApproximately 9,000
Individuals exposed (Google Workspace)1,646 (employees and business partners)
Data types exposedNames, email addresses
Threat actorNot attributed
Related falloutNikkei BP (sister publisher) employee credentials compromised

What Happened

The Google Workspace Account Compromise

Nikkei said an unauthorized party accessed an employee's Google Workspace account starting in late July 2026. The intrusion was discovered in early August 2026 after Google flagged suspicious account activity. According to Nikkei, the exposed data was limited to the names and email addresses of 1,646 individuals — described as employees and business partners — and did not include information belonging to readers or people interviewed by Nikkei reporters. Nikkei has not disclosed how the account's credentials were initially obtained.

The Microsoft 365 Account Hijack and Phishing Blast

In a separate incident, an attacker gained access to a Nikkei employee's Microsoft 365 account and, on September 30, 2026, used it to send roughly 9,000 emails containing links to malicious websites. Recipients included internal Nikkei staff as well as external contacts and sources that Nikkei journalists had previously interviewed. Because the messages originated from a legitimate, trusted Nikkei mailbox, recipients had no obvious reason to doubt their authenticity — a hallmark of business email compromise (BEC)-style phishing that abuses a real, internal sender identity rather than a spoofed domain.

Downstream Impact at Nikkei BP

Nikkei's sister publication, Nikkei BP, separately reported that one of its own employees received one of the phishing emails sent from the compromised Nikkei account and had their credentials compromised as a result — illustrating how a single hijacked mailbox inside a large media organization can cascade into additional account takeovers across affiliated business units.

Impact Assessment

Impact AreaDescription
Data exposureNames and email addresses of 1,646 people from the Google Workspace account; no reader or interviewee data in that breach
Phishing reachRoughly 9,000 recipients, including internal staff and journalists' outside sources
Trust abuseMalicious links distributed from a legitimate, recognized Nikkei sender address
Downstream compromiseA Nikkei BP employee's credentials were phished after receiving one of the malicious emails
ReputationalA major news organization's own infrastructure was weaponized against its staff and sources
Recurrence patternNikkei has disclosed multiple email- and credential-related security incidents in recent years

Recommendations

For Email Administrators

  • Enforce phishing-resistant multi-factor authentication (FIDO2/security keys or authenticator apps) on all Microsoft 365 and Google Workspace accounts, particularly for staff whose mailboxes carry high trust with external contacts (press, partners, sources).
  • Enable and review sign-in risk and anomalous-send alerts (Microsoft Entra ID Protection, Google Workspace security alerts) so a sudden spike in outbound mail volume from a single mailbox is caught before thousands of messages go out.
  • Use outbound mail-flow rules and rate limiting to cap how many external recipients a single account can message in a short window.

For Security Teams

  • Treat any confirmed account takeover as a potential pivot point: audit mail forwarding rules, OAuth app grants, and delegate access added to the compromised mailbox during the breach window.
  • Run a full message trace on any account confirmed compromised to identify every recipient of outbound phishing so each can be individually notified — as Nikkei did here.
  • Share indicators of compromise (malicious URLs from the September 30 campaign) with affiliated business units; Nikkei BP's downstream compromise shows lateral risk between sister organizations sharing contact lists.

For Recipients of Nikkei-Branded Emails

  • Do not click links in unexpected emails from Nikkei contacts, even from a previously trusted address, until the sender's identity is independently verified through a separate channel.
  • Delete and report any phishing email referencing this incident rather than forwarding or replying to it.
  • Watch for follow-up impersonation attempts — Nikkei has warned that attackers may continue to exploit the exposed contact information.

Key Takeaways

  1. Nikkei disclosed two unrelated breaches of employee email accounts — one Google Workspace, one Microsoft 365 — within a roughly two-month span.
  2. The Microsoft 365 compromise was used to send approximately 9,000 phishing emails on September 30, 2026, to both internal staff and external interview sources.
  3. The Google Workspace breach, active from late July to early August 2026, exposed names and email addresses of 1,646 people but not reader or interviewee data.
  4. Phishing sent from a legitimate, trusted internal mailbox is harder for recipients to detect than domain-spoofed phishing, raising the real-world success rate of such campaigns.
  5. The compromise cascaded beyond Nikkei itself: a Nikkei BP employee's credentials were phished after receiving one of the malicious emails.
  6. Nikkei has disclosed multiple security incidents in recent years, underscoring the need for sustained investment in account-takeover prevention across large media organizations with high-trust external contact networks.

Sources