Nikkei says attackers breached two email accounts, sent 9,000 phishing messages
One employee's Google Workspace account was accessed in late July, and a Microsoft 365 account was used in September to send phishing emails to staff and interviewees.
Nikkei has disclosed that unknown attackers recently breached two employee email accounts, according to bleepingcomputer.com. One of the accounts was used to send thousands of phishing emails.
An employee's Google Workspace account was accessed in late July, exposing personal information of employees and business partners. The breach may have exposed the names and email addresses of 1,646 individuals. Nikkei changed the account's password in early August after a notification from Google.
In a separate incident, threat actors accessed another employee's Microsoft 365 account in September and used it to send 9,000 phishing emails targeting Nikkei staff and interviewees. On September 30, emails containing links to malicious websites were sent to internal staff and interviewees.
Nikkei said it changed passwords following the incidents, and no unauthorized logins have been confirmed since.
Earlier incidents
Last year, Nikkei revealed that its Slack messaging platform had been breached, affecting more than 17,000 employees and business partners. In May 2022, Nikkei's Singapore subsidiary was hit by a ransomware attack that affected a server likely containing customer data. In late September 2019, Nikkei lost approximately $29 million in a business email compromise attack targeting a Nikkei America employee.
Quick answers
What did Nikkei disclose about the breach?
Nikkei said unknown attackers breached two employee email accounts: a Google Workspace account in late July and a Microsoft 365 account in September, which was used to send 9,000 phishing emails to staff and interviewees.
How many people were affected by the Google Workspace breach?
The Google Workspace breach may have exposed the names and email addresses of 1,646 individuals.
What did Nikkei do after the incidents?
Nikkei changed passwords for the affected accounts. The company said no unauthorized logins have been confirmed since.