SOCLYDE logo
Current languageEN
Cybersecurity newsCybersecurityData breachSecurity advisory

Nikkei discloses two email account incidents

Nikkei reports a compromised Microsoft 365 account and a separate Google Workspace access incident, raising phishing risks.

By Soclyde Team

A journalist reviews paper notes in a newsroom

In summary

  • Nikkei reported two separate incidents: an M365 account sent 9,000 phishing emails, and a Google account was accessed without authorization.
  • Recipients should verify unusual requests through a second channel, even when they come from a familiar account.
  • Nikkei and recipients should review accounts and report the messages; phishing-resistant MFA helps prevent another takeover.

Explore next

Soclyde resources

Article contents

Nikkei described two separate business account incidents. A compromised Microsoft 365 account sent about 9,000 phishing emails on September 30 to employees and sources. The company also discovered unauthorized access to a Google Workspace account dating back to late July.

Two environments, two incidents

Nikkei distinguishes the M365 account used to send messages from a Google Workspace account accessed without authorization. Public notices do not say the incidents are connected. The company says it changed the Google account password and knows of no further access afterward.

Potential consequences

The September 30 emails may contain phishing links. The M365 account could also expose names, email addresses and message contents. For the Google access, Nikkei cited potential personal data relating to 1,646 people. These possibilities do not mean every recipient or record was misused.

Why sources were targeted

A journalist’s inbox may contain sensitive exchanges and unpublished attachments. A message from a known account can therefore look credible to a colleague or source. Recipients should verify unusual requests through a second channel, especially if a message pressures them to open a document or enter credentials.

Actions for organizations

Teams can revoke active sessions, rotate secrets, inspect forwarding rules and review sign-in and sending logs. Recipients of the September 30 message should report it and avoid its links. Phishing-resistant MFA lowers the risk of another account takeover but cannot reverse earlier exposure.

How this relates to Soclyde

Soclyde does not secure Nikkei’s Microsoft or Google tenants. For teams, an encrypted vault can limit the spread of passwords and shared secrets and make rotation easier. Email account protection still depends on the provider’s identity, session and monitoring controls.

Key points

Keep the disclosed scope in view, while distinguishing observed access from confirmed misuse. Follow official updates and apply the steps relevant to your accounts. For team secrets, see our secure password sharing guide or contact Soclyde.

Frequently asked questions

Are the two Nikkei incidents connected?

Public notices describe them separately and do not confirm a link between the Microsoft 365 and Google Workspace accounts.

What if I received the email?

Do not open its links or attachments. Report it to your IT team and verify any request with your usual Nikkei contact through another channel.

What information may be involved?

Names, email addresses and message contents are cited for M365; the Google incident may involve data relating to 1,646 people.

References

Sources and references

Need advice?

Design your password strategy with Soclyde

Schedule a dedicated walkthrough with the team to see how local-first security adapts to your stack.

Talk with us

Keep reading