Nikkei, a Japanese publishing giant and owner of the Financial Times, has disclosed that two employee email accounts were breached by unknown attackers. The incidents exposed personal information of employees and business partners, with thousands of phishing emails sent to target Nikkei staff and interviewees.
The first breach occurred in late July when an employee’s Google Workspace account was accessed, exposing the names and email addresses of 1,646 individuals. However, Nikkei assures that no data related to readers or interviewees was compromised. The company changed the account password after discovering the breach in early August, following a notification from Google.
A more recent incident occurred in September when threat actors gained access to another employee’s Microsoft 365 account and used it to send 9,000 phishing emails targeting Nikkei staff and interviewees. These emails contained links to malicious websites designed to trick recipients into revealing sensitive information or installing malware on their devices.
Nikkei has not attributed the attacks to a specific threat actor or hacking group, nor has it revealed whether the two incidents are connected. The company has taken steps to mitigate the damage by changing passwords and warning affected individuals to be cautious of suspicious emails that may impersonate Nikkei or its subsidiaries.
The recent breaches mark the latest in a string of security incidents disclosed by Nikkei over the years. Last year, the company revealed that its Slack messaging platform was breached, affecting more than 17,000 employees and business partners. In May 2022, Nikkei’s Singapore subsidiary was hit by a ransomware attack that likely compromised customer data.
Nikkei’s security incidents highlight the importance of robust cybersecurity measures for organizations handling sensitive information. As one of the world’s largest media corporations, with over 3.7 million digital paid subscriptions and thousands of employees worldwide, Nikkei’s exposure to cyber threats is significant.
The company’s experience serves as a reminder that even large and well-established organizations can fall victim to sophisticated attacks. It emphasizes the need for businesses to stay vigilant and adapt their security strategies to address emerging threats.
In light of these incidents, individuals should be cautious when receiving unsolicited emails from Nikkei or its subsidiaries. They should verify the authenticity of such messages by contacting the company directly and avoid clicking on links or downloading attachments from unknown sources.
Source: Bleeping Computer — 2026-10-06