Security1 publisher2 min readPublished
Attackers used hijacked Nikkei accounts to send 9,000 phishing emails to staff and sources
Nikkei said attackers used hijacked staff Microsoft 365 accounts to send about 9,000 malicious-link emails on September 30, many to outside sources. The company believes recipients' names and addresses were exposed and expects more mail impersonating its staff.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- The emails came from genuine Nikkei accounts, so the sender address alone gave recipients little reason for suspicion.
- Nikkei has changed the affected passwords and says it has detected no further unauthorized logins since.
- In a separate breach, outsiders had been logged in to employee Google Workspace accounts since late July, possibly exposing data on 1,646 employees and business partners.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Nikkei's statement that no reader or source data leaked applies only to the Workspace breach, so it does not cover the outside sources who received the Microsoft 365 mail.
- capability An attacker holding correspondent names and parts of real messages can write follow-up lures that match conversations those contacts actually had with Nikkei staff.
- exposure If October 4 was Nikkei's first filing on the Workspace breach, it came about two months after discovery, under a rule that expects a preliminary report within three to five days.
At a newspaper, the people who have corresponded with employees include sources [3]. The report says numerous external sources and contacts received the September 30 mail [3]. The content of some messages is also believed to have been exposed, along with recipients' names and addresses [5]. Nikkei has contacted each recipient individually and asked them to delete the emails [7].
Nikkei warned that more spoofed emails posing as Nikkei or group company staff may follow. It asked anyone who gets a suspicious message to report it through its inquiry form [16]. "We ask everyone to remain vigilant against suspicious emails while we continue our investigation," the company said in a statement [17]. Nikkei has not said how the Microsoft 365 accounts were taken or whether the two intrusions are linked, and the report describes the Workspace breach as separate [8].
Google found the Workspace access, and Nikkei did not [9]. The intrusion started in late July and Google's notice came in early August [8][9]. That is a window of under a month [1]. The two-month gap in this incident comes after discovery. About two months passed between Google's notice and the October 4 announcement [2].
Japan's Act on the Protection of Personal Information makes reporting mandatory for breaches affecting more than 1,000 people [12]. At 1,646 people, the Workspace incident is over that threshold [3]. A preliminary report is due within roughly three to five days of discovery. The final report is due within 30 days, or 60 if the breach was carried out for malicious purposes [13]. The Cyber Express timeline puts Nikkei's report to the Personal Information Protection Commission on October 4, the same day as the public announcement [14]. Nikkei says it is still investigating the full scope and the number of personal records involved [15].
What to watch
- Nikkei's final reports to the Personal Information Protection Commission, due 30 days after discovery or 60 if the breach is judged malicious, and any revision to the 1,646 count.
- Any finding on how the Microsoft 365 accounts were taken and whether that intrusion connects to the Google Workspace access.
- Reports of further spoofed mail posing as Nikkei or group company staff, the follow-on the company has warned about.