INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Nikkei Discloses Breaches of Employees' Microsoft Google Email Accounts

| 2026-10-06 09:25 HIGH HIGH DATA BREACH
Executive Summary
AI-generated
In May 2022, Nikkei's Singapore subsidiary was hit by a ransomware attack that affected a server "likely" containing customer data. Recently, unknown attackers breached two employee email accounts in Japan and used one to send thousands of phishing emails over the weekend. In September, threat actors accessed another employee's Microsoft 365 account and used it to send 9,000 phishing emails targeting Nikkei staff and interviewees. The attacks are believed to be related to phishing campaigns impersonating Nikkei or its subsidiaries, with affected individuals being warned to watch for suspicious emails. As a result of the breaches, personal information was exposed in one incident affecting approximately 1,646 individuals, while another breach impacted over 17,000 employees and business partners on Nikkei's Slack messaging platform.
Technical Mitigations AI-generated
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity. • Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc • Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
SG JP
Incident Timeline
‎late September 2019
Threat actors used business email compromise (BEC) tactics to target a Nikkei America employee, resulting in the loss of approximately $29 million.
organisation BEC
financial $29 Nikkei
‎September 2019
Threat actors used phishing to breach employees' Microsoft and Google email accounts.
organisation the Financial Times
organisation NFL
organisation CHANEL
infrastructure 3.7 digital paid subscriptions
‎May 2022
Threat actors used ransomware to target Nikkei's Singapore subsidiary in May 2022.
target_region Singapore
tactic Ransomware
‎2025/10/06
Slack disclosed a breach of its messaging platform affecting over 17,000 employees and business partners in October 2025.
organisation Slack
victims 17,000 employees
‎September 30th
Threat actors sent emails containing links to malicious websites to internal staff and interviewees with whom several employees had been in contact.
‎2026/10/06
Threat actors accessed an employee's Microsoft 365 account in September to send thousands of phishing emails targeting Nikkei staff and interviewees.
infrastructure Microsoft 365
organisation Microsoft
organisation Google
organisation Google Workspace
organisation Nikkei
Tactical Metrics
Metrics
infrastructure
‎Microsoft 365
Affected Product
Metrics
victims
17,000
Employees
Metrics
financial
29,000,000
Financial Impact / Stolen Funds
Metrics
infrastructure
3,700,000
Digital Paid Subscriptions
Intelligence Sources