Nikkei, one of the world’s largest media corporations and owner of The Financial Times, has disclosed two recent security breaches that exposed employees’ personal information and led to a wave of phishing emails targeting staff and business partners.
The attacks occurred through employee email accounts on Microsoft 365 and Google Workspace. In late July, an unknown attacker accessed an employee’s Google account, exposing the names and email addresses of over 1,600 individuals. Nikkei has stated that the affected data does not include information about readers or interviewees. The company changed the password to the compromised account after discovering the breach in early August.
More recently, threat actors accessed another employee’s Microsoft 365 account in September, using it to send 9,000 phishing emails targeting Nikkei staff and interviewees. These emails contained links to malicious websites that could potentially compromise recipients’ devices or steal sensitive information. Nikkei has since changed its passwords and notified affected individuals of the potential threat.
The two breaches are part of a concerning trend for Nikkei, which has experienced multiple security incidents in recent years. Last year, the company disclosed that its Slack messaging platform had been breached, affecting over 17,000 employees and business partners. In 2022, Nikkei’s Singapore subsidiary was hit by a ransomware attack that targeted customer data. The company has also fallen victim to business email compromise (BEC) attacks in the past, with a notable incident occurring in 2019 that resulted in losses of over $29 million.
The impact of these breaches is significant not only for Nikkei but also for its employees and partners who may have received phishing emails. It highlights the importance of robust cybersecurity measures and employee education to prevent such incidents from happening in the first place. With the increasing sophistication of cyber threats, it’s essential for organizations to stay vigilant and proactive in protecting their networks and data.
For individuals affected by these breaches, it is crucial to be cautious when receiving unsolicited emails or messages that appear to come from Nikkei or its subsidiaries. Be wary of links to unfamiliar websites or requests for sensitive information. If you suspect a phishing attempt, delete the email immediately and contact the sender to verify the authenticity of the message. By staying informed and taking proactive steps to protect yourself, you can minimize the risk of falling victim to these types of attacks.
Source: Bleeping Computer — 2026-10-06