MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-10-06 · via BleepingComputer

Japanese Media Corporation Nikkei Confirms Compromised Employee Email Accounts Used for Mass Phishing

Image via BleepingComputer
Image via BleepingComputer

Publishing company Nikkei revealed that attackers breached employee email accounts hosted on Google Workspace and Microsoft 365, with one compromised account used to dispatch approximately 9,000 phishing emails targeting company staff and interview subjects. The earlier Google Workspace breach in July exposed contact information for roughly 1,600 individuals, while the September Microsoft incident led to widespread fraudulent email distribution before the company reset access. Nikkei is urging recipients to delete suspicious messages and watch for impersonation attempts in follow-up attack campaigns.

Expanded Detail

The breaches represent a concerning pattern of vulnerability across multiple cloud platforms. The July incident exposed basic contact details for approximately 1,600 people after unauthorized access to Google Workspace infrastructure, discovered only after Google notified the company. The September compromise proved more damaging operationally, as attackers leveraged a single Microsoft 365 account to orchestrate a large-scale phishing campaign, sending thousands of fraudulent messages before account access was reset.

Nikkei's security troubles extend beyond these recent incidents. The company has experienced multiple significant breaches over several years, including a 2019 business email compromise that resulted in nearly $30 million in financial losses and a previous Slack platform breach affecting tens of thousands of contacts. This recurring pattern suggests ongoing challenges in securing employee credentials and critical communication platforms.

Context

These breaches may undermine trust between major news organizations and their sources, as journalists' compromised accounts could be weaponized to impersonate legitimate news inquiries. Individuals targeted in phishing campaigns could face identity theft or credential theft risks. The incidents may also prompt broader scrutiny of cloud platform security practices and the responsibilities of large enterprises to implement multi-factor authentication and advanced threat detection systems. News organizations' vulnerability could have cascading effects on information security practices across media industries.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
Denmark Confirms Breach Exposing Population Data for Millions via Compromised Business Access · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Nikkei discloses breaches of employees' Microsoft, Google email accounts.” Browse more stories.