Nikkei confirms two employee cloud account breaches
Nikkei has disclosed unauthorised access to two employee cloud accounts, with one compromised Microsoft 365 mailbox used to send about 9,000 phishing emails to staff, journalistic contacts and other external recipients. The Japanese media group said on October 4 that a third party was believed to have logged into an employee’s Microsoft 365 account. On September 30, messages from the account were…
Nikkei has confirmed unauthorized access to two employee cloud accounts, with one compromised Microsoft 365 mailbox responsible for sending around 9,000 phishing emails to staff, journalists, and external recipients. The breach occurred on October 4, with third-party login believed to have taken place. On September 30, messages from the compromised account were sent within the company and to individuals who had communicated with several Nikkei employees, directing them to malicious websites.
Nikkei has changed the account password, confirming no further unauthorized logins occurred post the action. The company is notifying recipients individually to delete the messages and is cautioning them against opening suspicious emails. Nikkei has reported the incident to the Personal Information Protection Commission and continues to investigate the extent of the exposure.
The second incident involved an employee's Google Workspace account, which was accessed from outside the company from late July, potentially exposing 1,646 employees, business partners, and others' personal information. Nikkei learned of the Google Workspace access in early August following a Google notification, changing the affected account's password and confirming no further unauthorized logins.
Written by urgent.news from Arabian Post's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.