Executive Summary
On October 5, 2026, Nikkei Inc. publicly disclosed two separate breaches involving employee email accounts on both Microsoft 365 and Google Workspace platforms. The first incident involved the compromise of a Microsoft 365 account, which was subsequently used to send approximately 9,000 phishing emails to internal and external contacts, including journalistic sources and business partners. The phishing campaign leveraged the trust inherent in media communications and contained links to malicious websites. The second incident involved unauthorized access to a Google Workspace account beginning in late July 2026, potentially exposing the names and email addresses of 1,646 employees and business partners. Both incidents were detected and remediated by resetting passwords and notifying affected individuals. Nikkei Inc. reported the breaches to Japan's Personal Information Protection Commission and has found no evidence of further misuse of the exposed information as of the latest disclosures. No specific threat actor has been attributed, and no malware or advanced persistence mechanisms have been identified. The breaches highlight the risks of credential compromise and lateral phishing in cloud-based email environments, particularly within the media sector.
Technical Information
The breaches at Nikkei Inc. involved two distinct but related incidents of unauthorized access to cloud-based email accounts. The first incident targeted a Microsoft 365 account belonging to a Nikkei employee. The attacker gained access using compromised credentials and used the hijacked account to send approximately 9,000 phishing emails on September 30, 2026. These emails impersonated Nikkei staff and targeted both internal and external contacts, including journalistic sources and business partners. The phishing messages contained links to malicious websites, aiming to exploit the trust between journalists and their sources. This attack is classified as "lateral phishing," where a legitimate but compromised account is used to phish trusted contacts, increasing the likelihood of successful exploitation. The breach was detected after the phishing campaign, and the password for the affected account was changed. No further unauthorized logins were detected after remediation.
The second incident involved a Google Workspace account, which was accessed without authorization beginning in late July 2026. The breach was discovered in early August 2026 after Google issued a security alert to Nikkei. The attacker potentially accessed personal information of 1,646 employees and business partners, including names and email addresses. The password was reset upon discovery, and no subsequent unauthorized logins were detected. There is no evidence that the compromised data has been misused, and no information related to Nikkei readers or journalistic sources was exposed in this incident.
No specific malware or tools have been publicly identified in the available disclosures. The attack relied on credential compromise, likely via phishing or password reuse, rather than malware deployment. The phishing emails sent from the compromised Microsoft 365 account contained links to malicious websites, but the actual payload or phishing kit used has not been disclosed. No evidence of malware infection on endpoints or lateral movement beyond the compromised cloud accounts has been reported.
No specific threat actor or group has been attributed to these incidents as of the latest reporting. The techniques used—credential compromise, lateral phishing, and cloud account abuse—are common among both financially motivated cybercriminals and state-sponsored actors. Similar attacks have been observed in the media sector globally, where attackers compromise trusted accounts to target journalists, sources, and business partners. The lack of malware, ransomware, or advanced persistence mechanisms suggests a focus on data theft and phishing rather than destructive or extortion-based objectives.
The attack specifically targeted the media sector, exploiting the trust between journalists and their sources. The use of a hijacked account to send phishing emails to journalistic sources and business partners is a high-impact tactic in the media industry, where confidentiality and trust are paramount. The incident follows a pattern of increased targeting of Japanese companies, particularly in the media and business sectors, as noted in recent breach disclosures.
Mapping the attack methods to the MITRE ATT&CK framework, the following techniques are relevant:
Initial Access: Valid Accounts (T1078): The attacker gained access using legitimate credentials for Microsoft 365 and Google Workspace accounts. Phishing (T1566.002): The attacker used the compromised account to send phishing emails to trusted contacts (lateral phishing). Valid Accounts: Cloud Accounts (T1078.004): Abuse of cloud-based email accounts for persistence and further attacks.
Collection: Email Collection (T1114): The attacker accessed the content of emails and contact information.
Impact: Data Leak (T1537): Exposure of personal information, including names, email addresses, and email content.
Detection was achieved via security alerts (Google) and post-incident analysis (Microsoft 365). Remediation included password resets, direct notification to affected individuals, and regulatory reporting.
Attribution to a specific threat actor is not possible with current evidence (Low confidence), but the targeting of the media sector is clear (High confidence). All claims are supported by primary sources and technical analysis as cited in the References section.
Affected Versions & Timeline
The affected platforms were Microsoft 365 and Google Workspace accounts used by employees of Nikkei Inc. The incidents occurred as follows: Unauthorized access to a Google Workspace account began in late July 2026 and was discovered in early August 2026 after a security alert from Google. The Microsoft 365 account compromise was detected after a phishing campaign on September 30, 2026, during which approximately 9,000 phishing emails were sent. Both incidents were publicly disclosed by Nikkei Inc. on October 5, 2026. The company reported the breaches to Japan's Personal Information Protection Commission and began direct notification to affected individuals on the same day.
Threat Activity
The threat activity in these incidents centered on credential compromise and lateral phishing. In the Microsoft 365 incident, the attacker used a hijacked account to send phishing emails to internal and external contacts, including journalistic sources and business partners. The phishing emails contained links to malicious websites and impersonated Nikkei staff, leveraging the trust inherent in media communications. The Google Workspace incident involved unauthorized access to an employee account, potentially exposing the names and email addresses of 1,646 employees and business partners. No evidence of further misuse of the exposed information has been found as of the latest disclosures. The techniques used are common among both financially motivated cybercriminals and state-sponsored actors, and similar attacks have been observed in the media sector globally.
Mitigation & Workarounds
The following mitigation steps are recommended, prioritized by severity:
Critical: Enable multi-factor authentication (MFA) for all cloud-based email accounts, including Microsoft 365 and Google Workspace, to prevent unauthorized access via compromised credentials. Implement conditional access policies and login anomaly detection to identify and block suspicious authentication attempts.
High: Conduct regular reviews of OAuth applications and third-party integrations with cloud email platforms to minimize the risk of unauthorized access. Deploy message-level detection systems to identify unusual content, tone, timing, and sending volume in outbound emails, which can help detect lateral phishing campaigns.
Medium: Provide security awareness training to employees, focusing on phishing detection, credential hygiene, and reporting suspicious activity. Regularly audit account permissions and access logs for signs of unauthorized activity.
Low: Maintain up-to-date contact lists for incident response and ensure that all employees know how to report suspected phishing emails or account compromise.
References
https://www.nikkei.co.jp/nikkeiinfo/en/news/announcements/1555.html (2026-10-05), https://therecord.media/nikkei-cyberattack-japan-data (2026-10-05), https://www.adaptivesecurity.com/blog/nikkei-email-security-incident (2026-10-05)
About Rescana
Rescana provides a Third-Party Risk Management (TPRM) platform designed to help organizations identify, assess, and monitor risks in their digital supply chain. Our platform enables continuous monitoring of vendor security posture, automated evidence collection, and actionable risk insights to support incident response and compliance efforts. For questions about this report or to discuss how our capabilities can support your organization’s risk management, please contact us at info@rescana.com.



