Therecord.Media Nikkei Cyberattack Compromises Employee Accounts and Sends 9,000 Phishing Emails
Article Content
- •Nikkei reported two separate cyber incidents affecting employee email accounts.
- •Attackers sent 9,000 phishing emails using a compromised Microsoft 365 account.
- •Unauthorized access to a Google Workspace account may have exposed data of 1,646 individuals.
Japanese media group Nikkei disclosed two cyber incidents on October 4, 2026. The first incident involved attackers hijacking a Microsoft 365 account belonging to a Nikkei employee, sending approximately 9,000 phishing emails to internal and external contacts on September 30. The emails contained links to malicious websites and targeted individuals who had previously communicated with Nikkei employees. The second incident involved unauthorized access to a Google Workspace account since late July, potentially exposing personal information of 1,646 individuals, including employees and business partners. Nikkei has changed the passwords for the compromised accounts and reported both incidents to Japan's Personal Information Protection Commission. The company has not confirmed if the two breaches are connected and has detected no further unauthorized access since the incidents were discovered.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Dai-ichi Life in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What information was potentially exposed?
How should recipients handle the phishing emails?
What steps has Nikkei taken in response?
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…