Nikkei Cyberattack Hijacks Employee Accounts, Sends 9,000 Spoofed Emails
Nihon Keizai Shimbun disclos 2026-10-5 09:34:3 Author: thecyberexpress.com(查看原文) 阅读量:2 收藏

Nikkei cyberattack

Nihon Keizai Shimbun disclosed on October 4 that a Nikkei cyberattack had compromised employees’ Microsoft 365 business software accounts. Attackers then used those accounts to send roughly 9,000 spoofed emails to people inside and outside the company.  

The publisher also revealed a second, separate breach: a cloud service it uses had been accessed without authorization since late July, possibly exposing the personal information of 1,646 employees and business partners. 

In a statement, the company said: “We deeply apologize for the inconvenience and concern caused to all those affected. We ask everyone to remain vigilant against suspicious emails while we continue our investigation. We take this incident seriously and will further strengthen our security measures to ensure thorough information management.” 

How the Nikkei Cyberattack Unfolded?

A third party gained unauthorized access to the Microsoft 365 accounts that employees use for email and other work functions. On September 30, the attackers used the hijacked accounts to send about 9,000 emails containing links to malicious websites. The recipients included Nikkei staff as well as numerous external sources and contacts who had previously corresponded with employees. 

Because the messages came from Nikkei’s genuine accounts, the sender address alone gave recipients little reason for suspicion. The attack is believed to have exposed recipients’ names and email addresses, along with the content of some messages. 

Nikkei has since changed the affected passwords and says it has detected no further unauthorized logins. It has contacted each recipient individually and asked them to delete the emails. 

Google Workspace Breach Dates Back to July 

In a separate incident, outsiders also logged in to the Google Workspace cloud accounts that employees use for work. Since late July, names, email addresses and other information belonging to 1,646 people may have leaked. Nikkei learned of the problem in early August, when Google notified the company. According to Nikkei, the leaked data did not include information on readers or sources, and no secondary damage has been confirmed. 

The incidents unfolded in this order: 

  • Late July 2026: Unauthorized access to Google Workspace begins. 
  • Early August 2026: Nikkei discovers the access after Google notifies it. 
  • September 30, 2026: Attackers hijack Microsoft 365 accounts and send about 9,000 spoofed emails. 
  • October 4, 2026: Nikkei announces the incidents publicly and reports them to the Personal Information Protection Commission. 

Nikkei Cyberattack Reported to Regulator 

Nikkei has reported both incidents to Japan’s Personal Information Protection Commission. Under the Act on the Protection of Personal Information, organizations must report to the Commission and notify affected individuals when a breach caused by unauthorized access could harm people’s rights and interests. Breaches affecting more than 1,000 people are also subject to mandatory reporting.  

A preliminary report is due within roughly three to five days of discovery. A final report is due within 30 days, or within 60 days if the breach was carried out for malicious purposes. Nikkei is still investigating the full scope of the breach and the number of personal records involved. 

The company warned that spoofed emails posing as Nikkei or group company staff may increase. It asked anyone who receives a suspicious message to contact it through its inquiry form. 


文章来源: https://thecyberexpress.com/nikkei-cyberattack/
如有侵权请联系:admin#unsafe.sh