Nikkei Inc. Hit by Cyberattack Exposing Employee and Partner Data
Nikkei Inc. revealed on October 4 that its employees' Microsoft 365 accounts had fallen victim to a cyberattack. The breach allowed unauthorized access, leading to the sending of approximately 9,000 spoofed emails impersonating employees. Nikkei has since changed the affected passwords and confirmed no further unauthorized logins. The company is now reaching out to recipients of the suspicious emails, asking them to delete the messages.
Additionally, Nikkei disclosed that its Google Workspace accounts had experienced unauthorized external logins since late July. The breach, discovered in early August following a notification from Google, potentially exposed the email addresses and names of 1,646 individuals, including employees and business partners. Passwords were promptly changed, and no further unauthorized logins have been detected.
Reactions on X (formerly Twitter) highlighted the severity of the incident. Users expressed concern over the increasing frequency of cyberattacks, with comments such as "Nikkei too?! Isn't this serious?" and "This is the most malicious kind of hijacking attack. Nikkei's credibility has been exploited." Many also raised questions about corporate security measures in light of these successive breaches.