Nikkei confirms employee email breaches leading to phishing campaigns
Japanese media conglomerate Nikkei has revealed that two employee email accounts were compromised in separate incidents, leading to widespread phishing campaigns. In late July, attackers breached a Google Workspace account, exposing personal data of employees and business partners. The breach was discovered in early August after Google alerted Nikkei, prompting a password change. The exposed data included names and email addresses of 1,646 individuals but did not affect readers or interviewees.
More recently, in September, threat actors accessed a Microsoft 365 account and used it to send 9,000 phishing emails targeting Nikkei staff and interviewees. The emails contained links to malicious websites, and Nikkei has since changed passwords and contacted recipients to delete the suspicious messages. The company warned affected individuals to remain vigilant against further phishing attempts impersonating Nikkei or its subsidiaries.
Nikkei has not attributed the attacks to any specific group and has not confirmed a connection between the two incidents. The breaches add to a series of security incidents the company has faced in recent years, including a 2022 ransomware attack on its Singapore subsidiary and a $29 million business email compromise attack in 2019. Nikkei owns prominent publications like the Financial Times and operates globally with over 1,500 journalists and 3.7 million digital paid subscriptions.