Nikkei has disclosed separate compromises of two employee email accounts, one hosted on Google Workspace and the other on Microsoft 365. The Microsoft account was subsequently used to distribute 9,000 phishing messages to company personnel and external interviewees.
The incidents occurred in different months, and Nikkei has not attributed them to a threat actor or said they were connected. The available reporting also does not explain how attackers obtained access.
The source article describing Nikkei’s disclosure was published on October 6, 2026. It says the company disclosed the incidents over the weekend and released a statement on Sunday, without giving the statement’s exact date.
Google Workspace account exposed contact information
According to Nikkei, an attacker accessed an employee’s Google Workspace account in late July. The company said it learned about the breach in early August after receiving a notification from Google, then changed the account password.
Nikkei said names and email addresses belonging to 1,646 people may have been exposed. It described those individuals as employees and business partners.
That figure represents the number of people whose contact information was potentially involved. It is not a confirmed count of people whose data was viewed, copied or exfiltrated by the attacker.
The company said the affected data did not include information about readers or interviewees. No independent forensic findings have been provided to confirm the scope of account access or determine what actions the intruder performed inside the mailbox.
The reporting does not identify the specific Google alert that notified Nikkei. It also does not describe the authentication method used to compromise the account, such as stolen credentials, session-token theft, phishing or abuse of an account-recovery process.
Microsoft 365 compromise led to 9,000 phishing emails
A different employee account, this time on Microsoft 365, was accessed in September, Nikkei said. On September 30, the compromised account sent emails containing links to malicious websites.
Nikkei reported that 9,000 phishing emails targeted company staff and interviewees who had previously communicated with several employees. The number refers to messages sent, not necessarily 9,000 distinct recipients. It is also not a count of confirmed victims.
The available report does not say how many recipients opened the messages, followed their links or submitted information to the linked websites. Nor does it describe the websites’ behavior, payloads or intended data collection.
Using a genuine corporate mailbox can make phishing more persuasive because recipients may recognize the sender, the organization’s domain or an existing communication context. In this case, however, the specific content of the messages and the attacker’s ultimate objective have not been detailed.
Nikkei said it contacted recipients individually and instructed them to delete the phishing emails. The company also changed passwords and reported finding no unauthorized logins after those changes.
That statement describes Nikkei’s post-incident checks. It does not establish how long the attacker retained access before containment or whether the two compromised accounts were affected through the same technique.
No threat actor or common intrusion path identified
Nikkei has not named a suspected attacker, criminal service or state-linked group. It has also not said the Google Workspace and Microsoft 365 incidents formed part of one operation.
The timing alone does not demonstrate a connection. The accounts were hosted on different platforms, and the reported consequences differed: possible contact-data exposure in one case and outbound phishing in the other.
The account-access and response details come from Nikkei’s statements. The reporting available on October 6 does not include independent forensic confirmation, infrastructure analysis or technical evidence tying either breach to a known campaign.
There is also no formal severity score. Unlike a software vulnerability, an account compromise is not normally assessed through a CVSS rating. Its practical severity depends on factors including mailbox contents, the attacker’s access duration, connected services and what recipients did with malicious messages.
What employees and external contacts should do
Nikkei warned affected people to watch for suspicious communications impersonating the company or its subsidiaries. That risk can continue after password changes because names, addresses and existing business relationships may help attackers construct more credible follow-up messages.
Anyone who received the September 30 email should follow Nikkei’s instruction to delete it and avoid visiting its links. Recipients who already interacted with a linked site should report the event through their organization’s security channel and provide the original message where possible.
Potential recipients should scrutinize unexpected requests even when they originate from a familiar address. A separate, previously established channel can be used to verify requests involving credentials, payments, documents or changes to account details.
For organizations managing email systems, relevant defensive checks can include reviewing authentication records, active sessions, forwarding rules, mailbox delegation and third-party application access. These are general account-compromise response measures, not controls that Nikkei has publicly said it used.
The cited reporting does not provide malicious domain names, URLs or other indicators that defenders could search for directly. It also does not specify additional containment controls beyond password changes, recipient notifications and Nikkei’s review for subsequent unauthorized logins.
The incidents add to Nikkei’s security history
Nikkei owns the Financial Times and The Nikkei. The report describes the group as operating more than 40 affiliated companies spanning publishing, broadcasting, events, database services and index businesses.
Its international footprint includes 37 foreign editorial bureaus and more than 1,500 journalists worldwide. The company also has over 3.7 million paid digital subscriptions. That scale creates a broad network of employees, sources, interviewees and business partners who may communicate through corporate email.
The source article places the latest account breaches alongside several earlier incidents. “Last year,” in the source’s wording, Nikkei disclosed a compromise of its Slack environment affecting more than 17,000 employees and business partners. No calendar year should be inferred from that relative description.
In May 2022, a ransomware attack struck a server at Nikkei’s Singapore subsidiary that likely held customer data. In late September 2019, Nikkei lost approximately $29 million through a business email compromise scheme targeting an employee at Nikkei America.
Those earlier events do not establish who conducted the latest breaches or whether any technical relationship exists among them. They do, however, show that the newly disclosed compromises are not Nikkei’s first publicly reported incidents involving corporate communications or identity-based attacks.




