- Nikkei disclosed that an attacker used one employee's Microsoft 365 account to send about 9,000 phishing emails, including to journalistic sources.
- Recipients were inside and outside the company. Nikkei said their names, email addresses and some email contents may have been exposed.
- Leaders should ask how fast a misused mailbox is detected and how contacts are warned.
A mailbox is more than storage. It is a list of people who will open what you send them. When an attacker controls one account, they borrow that trust. In this case, recipients sat inside and outside the company.
What Nikkei disclosed
The Record reported that Nikkei disclosed two incidents involving employee email accounts on Sunday. In the newer case, an attacker took over a Microsoft 365 account assigned to one Nikkei employee. On September 30, that account sent roughly 9,000 phishing emails. Recipients included people inside and outside the company, and journalistic sources were among them.
The messages contained links to malicious websites. Nikkei said the targets were people who had earlier been in contact with its employees.
Why a real account is a strong disguise
Most phishing relies on a fake sender. This one did not need to fake anything. The messages came from a genuine Nikkei account and went to people who already knew Nikkei staff.
As general background, mail sent from a real mailbox carries the company's genuine sending identity. Defences built to catch spoofed senders have nothing to flag.
That is the mechanism. The attacker did not need to break into 9,000 inboxes. One account was enough, because the relationships built around it did the rest. A source who once wrote to a reporter has good reason to open a reply.
The Record's report does not say how the account was taken over. It does not say what the malicious links did.
Who is affected
Nikkei changed the account's password and has seen no further unauthorized access. It also reached out to recipients with a request to remove the messages. That deals with the account. It does not reach into the inboxes of the people who received the emails.
Nikkei said recipients' names, email addresses and the text of some messages may have been exposed. It has told Japan's data protection authority and is still counting affected people. It also cautioned that emails posing as its staff or group companies may become more common.
The Record's report does not say anyone clicked a link or was compromised. Still, the contacts now have to judge each message that appears to come from Nikkei. For a news organization, the contact list includes sources who chose to trust it. A company can restore an account quickly. Its contacts cannot easily tell the next genuine message from a fake one.
A second account, found by someone else
Earlier the same day, Nikkei reported a separate case. Someone had logged in to a Google Workspace account belonging to a different employee without permission, starting in late July. Nikkei said the personal details of 1,646 people, staff and business partners among them, may have been exposed.
Nikkei learned of the intrusion in early August, after Google sent it an alert. The company said the data could have included names and email addresses. It said no reader or journalistic-source information was involved, and it has found no evidence of misuse.
Nikkei has not said whether the two incidents are connected. Neither has been attributed to a hacking group.
One company, several disclosed incidents
These are not Nikkei's first disclosures. In November 2025, malware on an employee's computer captured credentials. Those credentials were then used to enter the company's internal Slack app. Nikkei said chat logs, names and email addresses linked to more than 17,000 staff and partners were potentially exposed.
The Record's report also lists other Japanese companies with recent incidents. Daiwa Securities, Japan's second-largest brokerage, traced a possible theft of data on up to 110,000 customers to a breach at an outside vendor. The report does not link these cases to Nikkei's. Taken together, they show that a breach can start with an account or with a supplier.
Questions to put to your team
First, how quickly would you know that one employee's mailbox was sending mail it should not? In the Google Workspace case, Nikkei learned of the intrusion from an alert sent by Google.
Second, who is on your contact lists, and can you warn them within hours? Nikkei contacted recipients of the phishing emails directly.
Third, which of your staff talk to people who could be targeted by a fake message from you: sources, patients, clients, suppliers? Those accounts may deserve more protection than their job titles suggest.
Fourth, do your vendors hold your customers' data on their own servers? In Daiwa's case, the company said its own systems were intact. The possible theft happened at the vendor.
The lesson is that a taken-over account does not stay inside the company. It lends your credibility to the people who have written to you.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: The Record.





