Particle.news

Nikkei Says Two Employee Cloud Accounts Were Compromised

Regulators and contacts face new risk after the breaches exposed names and messages from staff cloud accounts.

Overview

  • Nikkei disclosed that an employee Google Workspace account was accessed from late July and that a separate Microsoft 365 account was used on September 30 to send roughly 9,000 phishing emails to staff and people its journalists had contacted.
  • The company said the Google access may have exposed names and email addresses for 1,646 employees, partners and others while the Microsoft incident may have exposed recipients’ names, addresses and the content of some messages.
  • Nikkei changed the compromised account passwords, reported the incidents to Japan’s Personal Information Protection Commission, detected no further unauthorized logins and individually contacted recipients asking them to delete the phishing emails.
  • The firm has not attributed the activity to any known threat actor, has not said whether the two incidents are linked, and says formal forensic investigation is ongoing.
  • These disclosures add to a pattern of past breaches at Nikkei — including a 2025 Slack breach and earlier fraud and ransomware incidents — raising questions about how the group protects sources, partners and sensitive contact data.