Japanese media group Nikkei has disclosed unauthorized access to two employee cloud accounts, one of which was used to send around 9000 phishing emails to staff and to people its journalists had been in contact with.
In a statement published October 4, the company said an employee's Google Workspace account had been accessed from outside since late July, potentially exposing the names and email addresses of 1646 employees, business partners and others.
Nikkei learned of the access in early August through a notification from Google and changed the account's password immediately. It said it has seen no further unauthorized logins and has not confirmed any secondary harm.
The exposed information does not include details of readers or news sources, Nikkei said. It has reported the incident to Japan's Personal Information Protection Commission.
In a second disclosure the same day, Nikkei said an employee's Microsoft 365 account had been compromised and used on September 30 to send around 9000 emails directing recipients to malicious websites, both inside the company and to news sources and other contacts of several employees.
Hijacked Mailbox Used for Phishing
Nikkei said the recipients' names and email addresses, along with the content of some emails, may also have been exposed in the Microsoft 365 incident, which it has reported to the regulator and is still investigating.
The company changed the account's password, has detected no further unauthorized logins and contacted recipients individually to ask them to delete the emails. It warned that more suspicious messages posing as Nikkei or its group companies may follow.
Nikkei has not said how either of its own accounts was compromised, who was behind the activity or whether the two incidents are connected.
A Wider Pattern of Account Breaches
Group publisher Nikkei BP said separately on October 4 that an employee's email account was accessed on September 30 after their credentials were stolen through a phishing email sent from a Nikkei employee's address, potentially exposing 26 names and email addresses.
The disclosures follow a breach Nikkei reported in November 2025, when credentials stolen by infostealer malware on an employee's personal computer were used to access its Slack workspace, exposing data on 17,368 people. In 2019, Nikkei America lost about $29m in a business email compromise scam.
Nikkei said it will tighten its handling of personal information and its defenses against unauthorized access.
