The Japanese media giant Nikkei disclosed two cyber incidents involving employee email accounts on Sunday, joining a growing list of major Japanese companies hit by data breaches in recent weeks. In the more recent incident, an attacker compromised a Microsoft 365 account belonging to a Nikkei employee and used it to send roughly 9,000 phishing emails to people inside and outside the company, including journalistic sources. The emails sent on September 30 contained links directing recipients to malicious websites and targeted people who had previously communicated with Nikkei employees, the company said. Nikkei said it changed the password for the compromised account and has detected no further unauthorized access. It also contacted recipients and asked them to delete the malicious messages. The breach may have exposed recipients' names and email addresses, as well as the contents of some emails. Nikkei said it reported the incident to Japan's data protection authority and is still determining how many people had their personal information compromised. “There may be an increase in emails impersonating Nikkei employees or our group companies,” the company said. Earlier Sunday, Nikkei separately disclosed that a Google Workspace account used by another employee had been accessed without authorization beginning in late July, potentially exposing personal information belonging to 1,646 people, including employees and business partners. Nikkei discovered the intrusion in early August after receiving an alert from Google and changed the account password. The company said it has detected no subsequent unauthorized logins and has found no evidence that the potentially exposed information has been misused. The compromised data may have included names and email addresses but did not contain information related to Nikkei readers or journalistic sources, the company said. Nikkei has not said if the Google Workspace intrusion and the Microsoft 365 compromise were connected, and neither incident has been attributed to a specific hacking group. The disclosures add to a growing list of cyber incidents reported by Japanese companies in recent weeks. Daiwa Securities, Japan's second-largest brokerage, said Monday that information belonging to as many as 110,000 customers may have been stolen after hackers breached servers operated by an outside vendor. Daiwa said its own systems were not compromised and that the exposed information could not, by itself, be used to access accounts or execute trades. The delivery company Yamato Transport also recently disclosed unauthorized access to a payment service used for e-commerce purchases. Other Japanese companies reporting cyber incidents include insurer Dai-ichi Life, delivery company Sagawa Express and broadcast equipment manufacturer Ikegami Tsushinki. Nikkei is one of Japan's largest business media companies in the world. It publishes the financial newspaper The Nikkei, owns the Financial Times, employs more than 3,000 people and operates dozens of overseas editorial bureaus. The company has suffered several previous cyber incidents. In November 2025, Nikkei said an employee's computer had been infected with malware that stole credentials subsequently used to access the company's internal Slack app. The breach potentially exposed names, email addresses and chat histories associated with more than 17,000 employees and business partners. Nikkei said at the time that it had found no evidence that information concerning journalistic sources or reporting had been compromised. The company's Singapore headquarters was also hit by ransomware in 2022 in an incident that Nikkei said may have involved customer data.
No previous article
No new articles
Daryna Antoniuk
is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.