INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Nikkei Discloses Breaches of Employees' Microsoft Google Email Accounts
| 2026-10-06 09:25 HIGH HIGH DATA BREACH
Executive Summary
AI-generated
In May 2022, Nikkei's Singapore subsidiary was hit by a ransomware attack that affected a server "likely" containing customer data. Recently, unknown attackers breached two employee email accounts in Japan and used one to send thousands of phishing emails over the weekend. In September, threat actors accessed another employee's Microsoft 365 account and used it to send 9,000 phishing emails targeting Nikkei staff and interviewees. The attacks are believed to be related to phishing campaigns impersonating Nikkei or its subsidiaries, with affected individuals being warned to watch for suspicious emails. As a result of the breaches, personal information was exposed in one incident affecting approximately 1,646 individuals, while another breach impacted over 17,000 employees and business partners on Nikkei's Slack messaging platform.
Technical Mitigations AI-generated
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity.
• Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
SG
JP
Incident Timeline
late September 2019
Threat actors used business email compromise (BEC) tactics to target a Nikkei America employee, resulting in the loss of approximately $29 million.
Click on any entity below to view its context and source!
organisation
BEC
Three years earlier, in late September 2019,
Nikkei lost approximately $29 million
in a business email compromise (BEC) attack that targeted a Nikkei America employee.
financial
$29 Nikkei
Three years earlier, in late September 2019,
Nikkei lost approximately $29 million
in a business email compromise (BEC) attack that targeted a Nikkei America employee.
September 2019
Threat actors used phishing to breach employees' Microsoft and Google email accounts.
Click on any entity below to view its context and source!
organisation
the Financial Times
Nikkei owns the Financial Times and The Nikkei, the world's largest financial newspaper, and is one of the world's largest media corporations.
organisation
NFL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
infrastructure
3.7 digital paid subscriptions
It controls more than 40 affiliated companies involved in publishing, broadcasting, events, database services, and the index business, has 37 foreign editorial bureaus and over 1,500 journalists worldwide, and has over 3.7 million digital paid subscriptions.
May 2022
Threat actors used ransomware to target Nikkei's Singapore subsidiary in May 2022.
Click on any entity below to view its context and source!
target_region
Singapore
In May 2022, Nikkei's Singapore subsidiary
was hit by a ransomware attack
that affected a server "likely" containing customer data.
tactic
Ransomware
In May 2022, Nikkei's Singapore subsidiary
was hit by a ransomware attack
that affected a server "likely" containing customer data.
2025/10/06
Slack disclosed a breach of its messaging platform affecting over 17,000 employees and business partners in October 2025.
Click on any entity below to view its context and source!
organisation
Slack
Last year, the company also
revealed that its Slack messaging platform had been breached
, affecting more than 17,000 employees and business partners.
victims
17,000 employees
Last year, the company also
revealed that its Slack messaging platform had been breached
, affecting more than 17,000 employees and business partners.
September 30th
Threat actors sent emails containing links to malicious websites to internal staff and interviewees with whom several employees had been in contact.
2026/10/06
Threat actors accessed an employee's Microsoft 365 account in September to send thousands of phishing emails targeting Nikkei staff and interviewees.
Click on any entity below to view its context and source!
infrastructure
Microsoft 365
More recently, threat actors
accessed another employee's Microsoft 365 account
in September and used it to send 9,000 phishing emails targeting Nikkei staff and interviewees.
organisation
Microsoft
Nikkei discloses breaches of employees’ Microsoft, Google email accounts.
organisation
Google
Nikkei discloses breaches of employees’ Microsoft, Google email accounts.
organisation
Google Workspace
In a
Sunday statement
, the company said an employee's Google Workspace account was accessed in late July, exposing the personal information of employees and business partners.
organisation
Nikkei
While this incident may have exposed the names and email addresses of 1,646 individuals, Nikkei says the affected data doesn't include information about readers or interviewees.
Tactical Metrics
Metrics
infrastructure
Microsoft 365
Affected Product
Click for context!
More recently, threat actors
accessed another employee's Microsoft 365 account
in September and used it to send 9,000 phishing emails targeting Nikkei staff and interviewees.
Metrics
victims
17,000
Employees
Last year, the company also
revealed that its Slack messaging platform had been breached
, affecting more than 17,000 employees and business partners.
Metrics
financial
29,000,000
Financial Impact / Stolen Funds
Three years earlier, in late September 2019,
Nikkei lost approximately $29 million
in a business email compromise (BEC) attack that targeted a Nikkei America employee.
Metrics
infrastructure
3,700,000
Digital Paid Subscriptions
It controls more than 40 affiliated companies involved in publishing, broadcasting, events, database services, and the index business, has 37 foreign editorial bureaus and over 1,500 journalists worldwide, and has over 3.7 million digital paid subscriptions.
Intelligence Sources
BleepingComputer
2026-10-06
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T07:03
Comprehensive Tactical Telemetry
Highly Correlated Entities
9x
organisation
Identified Entity
Slack
entity
4x
timeline
Temporal Reference
May 2022
date
3x
tactic
Cyber Operation Type
Ransomware
tactic
2x
target region
Target Country
Singapore
country
Contextual Telemetry
Context Block
10 METRICS
infrastructure
Affected Product
Microsoft 365
software
general metric
Account
365
account
general metric
Phishing Emails
9,000
phishing emails
victims
Employees
17,000
employees
general metric
Individuals
1,646
individuals
financial
Financial Impact / Stolen Funds
29,000,000
nikkei
general metric
Affiliated Companies
40
affiliated companies
general metric
Editorial Bureaus
37
editorial bureaus
general metric
Journalists
1,500
journalists
infrastructure
Digital Paid Subscriptions
3,700,000
digital paid subscriptions
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.