Nikkei Inc. Reveals Cloud Email Breaches Exploiting Phishing and Data Exposure
Nikkei Inc. revealed two significant email account breaches involving its Microsoft 365 and Google Workspace platforms on October 5, 2026. The first incident involved a compromised Microsoft 365 account, which attackers used to send approximately 9,000 phishing emails to internal and external contacts, including journalistic sources and business partners. The phishing campaign exploited the trust inherent in media communications, with emails containing links to malicious websites.
The second breach involved unauthorized access to a Google Workspace account beginning in late July 2026. This incident potentially exposed the names and email addresses of 1,646 employees and business partners. Both breaches were detected and remediated by resetting passwords and notifying affected individuals. Nikkei Inc. reported the incidents to Japan's Personal Information Protection Commission and found no evidence of further misuse of the exposed information.
No specific threat actor has been attributed to these incidents. The attacks relied on credential compromise rather than malware deployment, highlighting the risks of lateral phishing in cloud-based email environments. The breaches underscore the vulnerabilities in media sector communications, where confidentiality and trust are paramount.