Nikkei Discloses Breaches of Employee Google and Microsoft Email Accounts

· Original article ↗

Summary

Nikkei says attackers accessed two employee email accounts: a Google Workspace breach may have exposed 1,646 people’s names and email addresses, while a Microsoft 365 account was used to send 9,000 phishing emails.

Key points

  • Attackers accessed an employee’s Google Workspace account in late July; Nikkei learned of the breach after Google notified it in early August.
  • The Google account breach may have exposed the names and email addresses of 1,646 employees and business partners, but not reader or interviewee data.
  • In September, attackers accessed another employee’s Microsoft 365 account and used it to send 9,000 phishing emails to Nikkei staff and interviewees.
  • The phishing emails, sent on September 30, contained links to malicious websites.
  • Nikkei changed the affected account passwords, reported no further unauthorized logins, contacted recipients, and asked them to delete the emails.
  • Nikkei has not identified the attackers or said whether the two incidents are connected.

Article Details

Victim Organization
Nikkei
Incident Type
Unauthorized access to two employee email accounts; one account was used to send phishing emails.
Incident Date
2026-09-30
Disclosure Date
2026-10-04
Data Types Exposed
  • Employee and business partner names and email addresses may have been exposed through the Google Workspace account.
Affected Records
Personal information of up to 1,646 individuals may have been exposed.
Operational Impact
Attackers used the Microsoft 365 account to send approximately 9,000 phishing emails to Nikkei staff and interviewees.
Claim Status
confirmed

MITRE ATT&CK

Vendors

Products

Countries

Industries

Related Articles