Skip to content
Nikkei Cyberattack Compromises Employee Accounts and Sends 9,000 Phishing Emails

Nikkei Cyberattack Compromises Employee Accounts and Sends 9,000 Phishing Emails

First seen 5 Oct 2026, 22:27 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 5, 2026 at 22:27 UTC
  • •Nikkei reported two separate cyber incidents affecting employee email accounts.
  • •Attackers sent 9,000 phishing emails using a compromised Microsoft 365 account.
  • •Unauthorized access to a Google Workspace account may have exposed data of 1,646 individuals.

Japanese media group Nikkei disclosed two cyber incidents on October 4, 2026. The first incident involved attackers hijacking a Microsoft 365 account belonging to a Nikkei employee, sending approximately 9,000 phishing emails to internal and external contacts on September 30. The emails contained links to malicious websites and targeted individuals who had previously communicated with Nikkei employees. The second incident involved unauthorized access to a Google Workspace account since late July, potentially exposing personal information of 1,646 individuals, including employees and business partners. Nikkei has changed the passwords for the compromised accounts and reported both incidents to Japan's Personal Information Protection Commission. The company has not confirmed if the two breaches are connected and has detected no further unauthorized access since the incidents were discovered.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-07-01
Unauthorized access to Google Workspace begins
Attackers accessed a Google Workspace account used by Nikkei employees, potentially exposing data of 1,646 individuals.
Thecyberexpress
2026-08-01
Nikkei discovers Google Workspace breach
Nikkei learned of unauthorized access to the Google Workspace account after receiving an alert from Google.
Thecyberexpress
2026-09-30
Phishing emails sent from compromised Microsoft account
Attackers used a compromised Microsoft 365 account to send 9,000 phishing emails to various recipients.
Therecord.Media
2026-10-04
Nikkei publicly discloses incidents
Nikkei announced the cyber incidents and reported them to Japan's Personal Information Protection Commission.
Thecyberexpress

More articles in this cluster (3)

Following this threat?

Track Dai-ichi Life in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What information was potentially exposed?
The Google Workspace breach may have exposed names and email addresses of 1,646 individuals, including employees and business partners.
How should recipients handle the phishing emails?
Recipients are advised to delete the malicious emails and remain vigilant against further phishing attempts.
What steps has Nikkei taken in response?
Nikkei has changed compromised account passwords and reported the incidents to the relevant authorities.