Nikkei’s staff and news sources received roughly 9,000 emails on September 30, 2026 that looked like ordinary correspondence from a colleague and carried a link to a malicious website. The messages came from a Microsoft 365 account assigned to a Nikkei employee, which an outsider had logged into without authorization. Nikkei disclosed the episode on October 4 and reported it to Japan’s Personal Information Protection Commission.
A second, older intrusion surfaced in the same pair of notices. A Google Workspace account used by another Nikkei employee had been open to an outside party since late July, and the two cases are described as separate incidents.
The September 30 mailbox flood
In its notice on the cyberattack and suspicious emails, Nikkei says about 9,000 spoofed emails went out from the compromised Microsoft 365 account on September 30. Recipients included colleagues inside the company and several outside contacts, among them news sources who had exchanged messages with the employee, and each message directed the reader to a malicious website. The notice does not break the 9,000 down by group.
Nikkei reset the account password, and says no further unauthorized logins have been confirmed since. It contacted recipients one by one and asked them to delete the messages, and it is still investigating how many people’s information was exposed. It told Japan’s Personal Information Protection Commission, the regulator for the country’s personal-information law, about the incident. The data likely involved is the names and email addresses of recipients, plus the contents of some emails. Nikkei also promised stronger security measures and set up an inquiry form for suspicious messages.
The mailing is notable for who received it. News sources who had corresponded with the employee are among Nikkei’s most sensitive contacts, and a message from that employee’s real account, linking to a site the recipient had no reason to distrust, is exactly the sort of lure a newsroom’s contacts are least likely to question. Nikkei’s response included individual outreach to those recipients rather than a general statement alone.
The Google Workspace login from late July
The other notice, titled “unauthorized login and information leakage”, concerns a Google Workspace account used for work. Nikkei says an outside party began logging in without authorization in late July, and that personal information belonging to employees and business partners may have leaked: about 1,646 individuals, with names and email addresses among the data, and readers and news sources excluded.
Google’s notification is how the company found out. Nikkei says that in early August Google alerted it, after which it changed the password, and that no secondary harm has been confirmed. BleepingComputer’s account of the two notices notes that Nikkei has not tied either intrusion to a specific group or said whether they are connected, and that it warned the public about phishing messages impersonating Nikkei or its subsidiaries.
Google’s early-August alert and Nikkei’s public notice of October 4 are about two months apart. The 1,646 count belongs to this Google Workspace case, not to the September 30 mailing. For the Microsoft 365 mailing, Nikkei states no count of exposed individuals.
Mailbox takeover and the Microsoft 365 clean-up
Microsoft’s guidance on responding to a compromised email account says attackers “often use a compromised user’s mailbox to send to recipients inside and outside of the organization.” Microsoft adds that attackers also use mailbox settings, such as rules that forward mail to unknown addresses, to keep access and hide what they are doing, and that app passwords are not revoked automatically when a password is reset. It calls disabling the account “preferred and highly recommended” until the investigation is finished, advises revoking active sessions because that “immediately invalidates any active access using the stolen credentials,” and lists forwarding rules and unexplained password changes among the signs of a takeover.
Nikkei has been here before. In November 2025 the company disclosed that stolen credentials, taken after malware infected an employee’s computer, had let attackers into Slack and exposed the names, email addresses and chat histories of 17,368 people, according to that disclosure. It said then that no information related to sources or reporting activities had been confirmed leaked.
BleepingComputer’s review of the company’s record lists earlier episodes as well: a ransomware attack on a server at its Singapore subsidiary in May 2022, and a September 2019 business email compromise aimed at a Nikkei America employee that cost about $29 million. In the 2025 Slack case Nikkei said the stolen information fell outside the scope of Japan’s personal-information law, which mandates reporting for certain breaches, yet notified the commission voluntarily anyway.
Nikkei’s October notice gives one hard number for the mailing, about 9,000 messages, and leaves the count of people whose data was exposed open while it investigates.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview
- NOAA now gives this winter a 75% chance of the strongest El Nino since 1950
- Doctors warn a silent liver disease now affects one in three American adults
- The FBI told the rest of ShinyHunters to surrender after a 24-year-old was arrested
- Two passengers died at an Ohio toll plaza, and the NTSB now wants the cash lanes shut