Japanese media organization Nikkei has disclosed that an attacker compromised an employee’s Microsoft 365 account and used it to send approximately 9,000 phishing emails to recipients inside and outside the company.
The September 30 messages contained links to malicious websites and reached people who had previously communicated with Nikkei employees. Recipients included journalistic sources, creating potential risks to confidential reporting relationships as well as ordinary account and credential security.
Nikkei changed the compromised account’s password, contacted recipients and instructed them to delete the messages. The company said it has not detected additional unauthorized access since taking those actions.
PHISHING EMAILS TARGETED ESTABLISHED CONTACTS
Using a genuine employee account can make phishing significantly more convincing than messages sent from a lookalike domain.
The attacker could send messages from Nikkei’s legitimate Microsoft 365 environment to people with existing relationships with the compromised employee. Familiar names, authentic email addresses and potentially genuine conversation context can make recipients more likely to trust a malicious link.
Nikkei warned that the incident could lead to additional emails impersonating its employees or affiliated companies. Anyone receiving an unexpected message from Nikkei should verify it through a separate communication channel before following links, opening attachments or providing credentials.
EMAIL CONTENT AND CONTACT INFORMATION MAY HAVE BEEN EXPOSED
Nikkei said the compromised account may have exposed recipients’ names, email addresses and the contents of some messages.
The company is still determining how many people had personal information compromised. It reported the incident to Japan’s data-protection authority.
The possible exposure of message content is particularly sensitive for a news organization. Email correspondence could identify confidential sources, reveal reporting interests or provide contextual information that attackers could use in targeted phishing and impersonation campaigns.
Nikkei has not confirmed that confidential source communications were stolen or published. The confirmed finding is that journalistic sources received phishing emails from the compromised account and that some email data may have been accessible.
A SECOND EMPLOYEE ACCOUNT WAS ACCESSED
Nikkei separately disclosed unauthorized access involving a Google Workspace account used by another employee.
That intrusion reportedly began in late July and was discovered in early August after Google issued an alert. Personal information belonging to as many as 1,646 employees and business partners may have been exposed, including names and email addresses.
Nikkei said the Google Workspace account did not contain information related to readers or journalistic sources. The company has not found evidence that the potentially exposed information was misused.
The organization has not established a connection between the Google Workspace intrusion and the later Microsoft 365 phishing incident. They should therefore be treated as separate investigations unless evidence links them.

