Nikkei described two separate business account incidents. A compromised Microsoft 365 account sent about 9,000 phishing emails on September 30 to employees and sources. The company also discovered unauthorized access to a Google Workspace account dating back to late July.
Two environments, two incidents
Nikkei distinguishes the M365 account used to send messages from a Google Workspace account accessed without authorization. Public notices do not say the incidents are connected. The company says it changed the Google account password and knows of no further access afterward.
Potential consequences
The September 30 emails may contain phishing links. The M365 account could also expose names, email addresses and message contents. For the Google access, Nikkei cited potential personal data relating to 1,646 people. These possibilities do not mean every recipient or record was misused.
Why sources were targeted
A journalist’s inbox may contain sensitive exchanges and unpublished attachments. A message from a known account can therefore look credible to a colleague or source. Recipients should verify unusual requests through a second channel, especially if a message pressures them to open a document or enter credentials.
Actions for organizations
Teams can revoke active sessions, rotate secrets, inspect forwarding rules and review sign-in and sending logs. Recipients of the September 30 message should report it and avoid its links. Phishing-resistant MFA lowers the risk of another account takeover but cannot reverse earlier exposure.
How this relates to Soclyde
Soclyde does not secure Nikkei’s Microsoft or Google tenants. For teams, an encrypted vault can limit the spread of passwords and shared secrets and make rotation easier. Email account protection still depends on the provider’s identity, session and monitoring controls.
Key points
Keep the disclosed scope in view, while distinguishing observed access from confirmed misuse. Follow official updates and apply the steps relevant to your accounts. For team secrets, see our secure password sharing guide or contact Soclyde.



