Nikkei: hijacked Microsoft 365 staff account sends about 9,000 phishing emails to colleagues and news sources (30 Sep); Nikkei BP and an earlier Google Workspace account also breached
Nikkei Inc., the Japanese media group that owns the Financial Times, said on 4 October 2026 (English notice 5 October) that a Microsoft 365 account used by one of its employees was accessed by a third party and used on 30 September to send about 9,000 spoofed emails with links to malicious websites, to staff and to news sources and others who had been in contact with several Nikkei employees. Nikkei believes recipients' names and email addresses and the content of some emails were exposed. It changed the account password, has seen no unauthorised logins since, asked recipients to delete the emails, reported the incident to Japan's Personal Information Protection Commission and is still working out the scope and the number of records involved. Group company Nikkei BP said separately on 4 October that one of its employees handed over login details to a phishing email that came from a Nikkei staff address, exposing 26 names and email addresses. BleepingComputer reports Nikkei also disclosed that an employee's Google Workspace account was accessed in late July, exposing names and email addresses of 1,646 employees and business partners but not reader or interviewee data, which Nikkei found in early August after a Google notification. No attacker has been named and Nikkei has not said whether the incidents are connected. Primary: Nikkei Inc. notice.
- Product
- Employee Microsoft 365 and Google Workspace email accounts (Nikkei Inc., Nikkei BP)
- Versions
- n/a — account compromise; no CVE or product flaw identified
- Exploited in Australia?
- no
- Patch to
- Anyone who received email from a Nikkei or Nikkei BP address around 30 September should delete it and not open its links. For email account takeovers, a password reset is not the end of the job: revoke active sessions and refresh tokens, check MFA methods, OAuth app consents, inbox and forwarding rules and sign-in logs, and use phishing-resistant MFA with Conditional Access. Alert on one mailbox suddenly sending thousands of messages.
Primary: Nikkei Inc. — Regarding information leaks and the sending of suspicious emails due to a cyberattack (5 Oct 2026; Japanese notice 4 Oct) · Vendor: Nikkei BP — Personal information leak through unauthorised email access (Japanese, 4 Oct 2026) · BleepingComputer — Nikkei discloses breaches of employees' Microsoft, Google email accounts (6 Oct 2026)
