Nikkei Shimbun Discloses Email Breach and 9,000-Message Phishing Attack
Japanese publishing giant Nikkei Shimbun has disclosed two recent email security incidents involving compromised employee accounts, leaked personal information and a phishing campaign that sent approximately 9,000 malicious emails.
Google Workspace breach exposed employee and partner information
In a Sunday statement, Nikkei Shimbun said attackers accessed employees’ Google Workspace accounts in late July. One compromised account was then used to send thousands of phishing emails.
The company discovered the breach in early August after receiving a notification from Google. Nikkei subsequently changed the affected account’s password.
The incident may have exposed the names and email addresses of 1,646 people, including employees and business partners. Nikkei said the exposed information did not include data belonging to its readers or interviewees.
Microsoft 365 account used to send 9,000 phishing emails
In a separate incident, threat actors accessed another employee’s Microsoft 365 account in September. The account was used to send approximately 9,000 phishing emails to Nikkei employees and interviewees.
“On September 30th, an email containing a link to a malicious website was sent to internal staff and interviewees with whom several employees had been in contact,” the media company said. “We have changed passwords and have not seen any unauthorized logins since then. We have contacted recipients individually and asked them to delete the email.”
Nikkei also warned affected individuals to remain alert for suspicious messages impersonating Nihon Keizai Shimbun or its subsidiaries as part of a potential follow-up phishing campaign.
Nikkei has not attributed the attacks
Nikkei Shimbun has not identified a specific attacker or hacking group responsible for either incident. The company also has not disclosed whether the Google Workspace and Microsoft 365 compromises are related.
Previous Nikkei security incidents
The disclosures are the latest in a series of security incidents reported by Nikkei in recent years. The company previously revealed that its Slack messaging platform had been compromised, affecting more than 17,000 employees and business partners.
In May 2022, Nikkei Shimbun’s Singapore branch was hit by a ransomware attack that affected servers that “may” have contained customer data.
Three years earlier, in late September 2019, a Japanese company suffered approximately $29 million in losses from a business email compromise (BEC) attack targeting its Japanese American employees.
About Nikkei Shimbun
Nikkei Shimbun owns the Financial Times and the Nikkei Shimbun, the world’s largest economic newspaper, and is one of the world’s largest media companies.
The company manages more than 40 affiliate companies across publishing, broadcasting, events, database services and indexing. It also operates 37 international editorial offices and has more than 1,500 journalists worldwide, along with more than 3.7 million digital paid subscriptions.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



