Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Oct 06, 2026 · 8 min read

Nikkei Cyberattack: One Account Sent 9,000 Phishing Emails

On September 30, 2026, an attacker logged into a Nikkei employee's Microsoft 365 account and sent about 9,000 emails with links to malicious websites, some of them to news sources. The same weekend, Nikkei disclosed a separate Google Workspace intrusion that began in late July, and its sister publisher Nikkei BP said one of the phishing emails cost it an employee's credentials.

The most dangerous phishing email is the one that really does come from someone you know. On September 30, roughly 9,000 of them went out to people who had corresponded with Nikkei staff: messages from a genuine Nikkei mailbox, carrying links to malicious sites. Nikkei's English disclosure says the recipients included "news sources and others who had previously communicated with multiple Nikkei employees."

For a newsroom, that recipient list is the story. It is a map of who talks to Nikkei reporters, and the attacker was holding it.

Key Takeaways

  • Nikkei Inc. says a third party logged into one employee's Microsoft 365 account and, on September 30, 2026, sent approximately 9,000 spoofed emails with links to malicious websites.
  • Recipients included Nikkei staff and outside contacts such as news sources, and Nikkei believes their names, email addresses and the content of some emails leaked.
  • Nikkei BP, a sister publisher, says one of its employees lost login credentials to a phishing email sent from a Nikkei employee's address, exposing 26 names and email addresses.
  • A separate Google Workspace account was accessed from late July, discovered in early August after a Google notification, and may have exposed names and email addresses of 1,646 people; Nikkei says that incident did not include reader or source information.
  • Nikkei's Microsoft 365 disclosure makes no equivalent promise about sources, and the company has not said whether the two intrusions are connected.
A dark Tokyo newspaper newsroom at night with rows of empty desks and a single monitor glowing with an email inbox

What Happened in the Nikkei Cyberattack?

Two Nikkei employee accounts on two different cloud platforms were taken over, months apart, and Nikkei disclosed both on October 4, 2026. According to The Record, the Google Workspace account was "used by another employee," so these were two separate people.

  • Late July: Unauthorized logins to a Nikkei employee's Google Workspace account begin, per Nikkei's Japanese notice.
  • Early August: A notification from Google tips Nikkei off. The password is changed and no further logins are seen.
  • September 30: A Nikkei employee's Microsoft 365 account sends about 9,000 emails pointing to malicious sites. Nikkei BP says one of its employees' mailboxes was accessed without authorization that day, using credentials phished by one of those emails.
  • October 4: Nikkei publishes Japanese notices on both incidents, and Nikkei BP publishes its own.
  • October 5: Nikkei posts the English version of the Microsoft 365 notice.

Nikkei reported both incidents to Japan's Personal Information Protection Commission. For the Microsoft 365 case it is still "investigating the scope of the breach and the number of personal information records affected."

Are the Google Workspace and Microsoft 365 Breaches Connected?

Nobody has said so. "Nikkei has not said if the Google Workspace intrusion and the Microsoft 365 compromise were connected, and neither incident has been attributed to a specific hacking group," The Record reported.

The link that is confirmed runs sideways, to Nikkei BP. Its notice says the affected employee had credentials taken through "a phishing email that arrived from a Nikkei employee's email address" (our translation of 日本経済新聞社社員のメールアドレスで届いたフィッシングメール). Nikkei BP cut off access to the account and says 26 names and email addresses may have leaked. That is the clearest public evidence of what the 9,000 messages were for. They were credential harvesting, not just spam.

Neither company has named the phishing kit, the landing page or whether the hijacked accounts had multifactor authentication. Nikkei's notices mention password changes; they do not mention revoking active sessions.

Were Nikkei's Journalistic Sources Exposed?

Nikkei has only ruled out source exposure for the Google Workspace incident, not for the Microsoft 365 one. The Google Workspace notice says the potentially leaked data on 1,646 people contains nothing about readers or news sources (読者や取材先に関するものは含まれていません). The Microsoft 365 notice has no such line. It says the opposite in practice: sources were among the recipients, and "recipients' names and email addresses, as well as the content of some emails" are believed to have leaked.

Published the same day, the two notices are easy to read as one blanket reassurance. They are not. The "no sources" line belongs to the smaller incident, and The Record drew that distinction. An attacker who mails a newsroom's contacts already knows who those contacts are, and Nikkei says some message content went with them.

The omission stands out against Nikkei's earlier statements. After its 2025 Slack breach it said it had found no leakage of information related to sources. This time it has not repeated that claim. For a reporter, a contact list is sensitive even without the stories attached, which is why stolen journalist data keeps surfacing on the dark web.

Why Email Users Should Care: The Sender Was Real

Account takeover phishing beats the checks most people rely on. SPF, DKIM and DMARC confirm a message came from the domain it claims, and mail sent from Nikkei's own Microsoft 365 account would pass them. The display name is right. The thread history may be right. Only the link is wrong.

Scale makes it worse. The Record says Nikkei employs more than 3,000 people, so 9,000 messages is about three for every employee on the payroll, sent from a single mailbox in a single day. Nikkei also warns that "There may be an increase in emails impersonating Nikkei employees or our group companies," so the follow on wave may come from lookalike addresses rather than real ones.

This is the fourth disclosed account compromise at the Nikkei group in under a year:

  • November 2025: Malware on an employee's PC leaked Slack credentials, exposing names, emails and chat histories for 17,368 people.
  • May 2026: A Nikkei America Microsoft 365 account sent impersonation emails to business partners in early March; up to 291 people affected.
  • July to August 2026: The Google Workspace intrusion, 1,646 people.
  • September 2026: The Microsoft 365 account that sent 9,000 emails.

The March case is the same playbook at a smaller size: one mailbox, messages to people who had written to it, and Nikkei America only found out when a recipient contacted it. The same US subsidiary lost about $29 million to a fake executive in 2019, as Infosecurity Magazine reported. Seven years on, the attacker no longer needs to fake the sender.

How Can You Spot Phishing From a Real Colleague's Account?

Judge the request, not the sender. When a message comes from a known contact, the address and authentication results will look clean, so the signals have to come from what the email asks you to do.

  1. Treat any unexpected link that ends at a login page as hostile. Before typing a password, read the domain in the address bar. A Microsoft or Google sign in should sit on that company's own domain.
  2. Verify out of band. Call or message the sender on a number or app you already had. Do not reply to the email, since the attacker controls that mailbox.
  3. Watch for tone and context breaks. A contact who always writes to you in Japanese suddenly sending a generic English "shared document" note, or any message unrelated to your last exchange, is a warning sign.
  4. If you clicked and signed in, act now. Change the password, sign out all sessions, and check your own mailbox for new forwarding or inbox rules. Nikkei BP's case shows one click can turn a recipient into the next sender.
  5. Report it to the impersonated organization. Nikkei asks anyone who gets a suspicious email to use its inquiry form.

Sources who received a Nikkei email on September 30 should assume their address and their link to Nikkei are now known to a third party, and choose channels for future contact with that in mind.

What Should Security Teams Do After a Mailbox Takeover?

Contain the session as well as the password, then hunt for persistence. Microsoft's guide to responding to a compromised email account notes that "Attackers often use a compromised user's mailbox to send to recipients inside and outside of the organization," which is what happened at Nikkei.

  • Revoke sessions, not just passwords. Microsoft lists Revoke-MgUserSignInSession as its own step, to "invalidate existing refresh tokens" for the user. Stolen tokens are how AiTM kits keep Outlook access after MFA.
  • Audit inbox rules, including hidden ones. Run Get-InboxRule -IncludeHidden and check mailbox forwarding. Rules that hide replies are a staple of Storm-2755's payroll hijacks.
  • Remove rogue MFA methods and app consents the attacker may have registered.
  • Use message trace to build the full recipient list, then warn every recipient directly, as Nikkei did.
  • Move to phishing resistant MFA. CISA calls FIDO/WebAuthn and PKI based methods "the gold standard," and says organizations "should make migrating to it a high priority effort."
  • Alert on bulk outbound mail. Conditional access on risky sign ins, plus a threshold alert on sudden sending spikes, would flag 9,000 messages from one user in a day.

For compliance teams, the reporting lesson is the Nikkei BP notice itself. A sister company found the compromise, cut access, reported to the Personal Information Protection Commission and published its notice on October 4, the same day as the parent. Group wide incident response should assume that a hijacked mailbox will target colleagues at affiliates first, because they trust the sender most.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.