Japanese Media Corporation Nikkei Confirms Compromised Employee Email Accounts Used for Mass Phishing

Publishing company Nikkei revealed that attackers breached employee email accounts hosted on Google Workspace and Microsoft 365, with one compromised account used to dispatch approximately 9,000 phishing emails targeting company staff and interview subjects. The earlier Google Workspace breach in July exposed contact information for roughly 1,600 individuals, while the September Microsoft incident led to widespread fraudulent email distribution before the company reset access. Nikkei is urging recipients to delete suspicious messages and watch for impersonation attempts in follow-up attack campaigns.
The breaches represent a concerning pattern of vulnerability across multiple cloud platforms. The July incident exposed basic contact details for approximately 1,600 people after unauthorized access to Google Workspace infrastructure, discovered only after Google notified the company. The September compromise proved more damaging operationally, as attackers leveraged a single Microsoft 365 account to orchestrate a large-scale phishing campaign, sending thousands of fraudulent messages before account access was reset.
Nikkei's security troubles extend beyond these recent incidents. The company has experienced multiple significant breaches over several years, including a 2019 business email compromise that resulted in nearly $30 million in financial losses and a previous Slack platform breach affecting tens of thousands of contacts. This recurring pattern suggests ongoing challenges in securing employee credentials and critical communication platforms.
These breaches may undermine trust between major news organizations and their sources, as journalists' compromised accounts could be weaponized to impersonate legitimate news inquiries. Individuals targeted in phishing campaigns could face identity theft or credential theft risks. The incidents may also prompt broader scrutiny of cloud platform security practices and the responsibilities of large enterprises to implement multi-factor authentication and advanced threat detection systems. News organizations' vulnerability could have cascading effects on information security practices across media industries.