Key takeaways

  • Nikkei (日本経済新聞社), publisher of Japan's leading business newspaper, disclosed two separate account breaches on October 4, 2026.
  • In one, attackers took over an employee's Microsoft 365 account and on September 30 sent about 9,000 phishing emails, including to news sources who had been in contact with Nikkei staff. Recipients' names and addresses, and the content of some emails, are believed to have leaked.
  • In the other, an employee's Google Workspace account was accessed from late July. Nikkei found out in early August when Google notified it. Data on 1,646 people may have leaked.
  • These are the third and fourth takeovers of a Nikkei cloud work account disclosed in under a year, after Slack (November 2025) and a Microsoft 365 account at its US subsidiary (May 2026).

What happened#

Microsoft 365: phishing sent to news sources#

According to Nikkei's notice:

  • An employee's Microsoft 365 account was attacked. Nikkei believes a third party logged in without authorization.
  • On September 30, about 9,000 impersonation emails were sent from the account, leading to malicious websites. They went to people inside Nikkei and to news sources and others who had exchanged emails with several Nikkei employees.
  • The names and email addresses of recipients, and the content of some emails, are believed to have leaked.
  • Nikkei changed the password and has seen no unauthorized logins since. It contacted recipients individually and asked them to delete the emails.
  • It has reported the incident to the Personal Information Protection Commission and is still investigating the scope and the number of people affected.

Nikkei warns that more emails impersonating Nikkei and group company staff may follow.

Google Workspace: found by Google#

In a separate notice the same day:

  • An employee's Google Workspace account, used for work, was logged in to from outside without authorization from late July.
  • Nikkei learned of it in early August through a notification from Google. It changed the password and has seen no unauthorized logins since.
  • Email addresses, names and other data on 1,646 people, including employees and business partners, may have leaked. Nikkei says no reader or news source data is included, and no secondary harm has been found.
  • It has reported the incident to the Personal Information Protection Commission.

Four in under a year#

Disclosed Service What happened People How it was found
Nov 2025 Slack An employee's personal PC was infected with malware, and the Slack credentials stolen from it were used to log in 17,368, including chat history Not stated
May 2026 Microsoft 365 (Nikkei America) Impersonation emails sent to business partners in early March 291 A business partner got in touch
Oct 2026 Google Workspace Unauthorized logins from late July 1,646 Notification from Google
Oct 2026 Microsoft 365 About 9,000 phishing emails sent on Sep 30, including to news sources Under investigation Not stated

The Slack breach is the only one where Nikkei has explained how the attackers got the credentials.

What we don't know yet#

Nikkei has not said:

  • How the attackers obtained access to the Microsoft 365 and Google Workspace accounts
  • Whether the accounts used multi-factor authentication
  • How the September 30 phishing was detected
  • What the malicious websites did, such as stealing passwords, and whether any recipients entered details
  • Why the Google Workspace breach, found in early August, was disclosed two months later
  • Whether the incidents are connected

Our analysis#

The attackers used a real employee's mailbox#

The Microsoft 365 emails did not come from a look-alike address. They came from a real Nikkei account, to people who had actually corresponded with Nikkei staff. A source who receives an email from Nikkei staff they know has every reason to open it. That is what makes a compromised mailbox more dangerous than ordinary phishing, and why the victims of this incident are not only Nikkei but its contacts.

For a news organization, the recipient list matters in itself. Nikkei says the names and addresses of recipients, including news sources, and some email content are believed to have leaked. Who a newspaper's staff correspond with is sensitive information. In its Slack notice, Nikkei pointed out that personal data held for reporting purposes is exempt from the breach reporting duty under Japan's privacy law, and that it reported voluntarily. It has again reported this case to the regulator.

Found by others#

In two of the four incidents, Nikkei learned of the breach from outside: a business partner in the US case, and Google in the Google Workspace case. In the Google Workspace case, unauthorized access had continued from late July until Google's notification in early August. Nikkei has not said how it detected the September 30 phishing.

"We changed the password"#

Each of the four notices describes changing the password as the main response, and none mentions multi-factor authentication. From the notices alone, readers cannot tell whether it was in use. As a general point, though, when credentials are stolen by malware, as in the Slack case, the session tokens that keep a user logged in are often stolen too, so a password reset alone may not be enough to cut off access.

Four account takeovers across Slack, Microsoft 365 and Google Workspace in under a year suggest that the problem is not one product. The notices promise to "further strengthen security measures", but say nothing about what changed after each incident.

Three platforms, three sets of accounts#

Nikkei employees used Slack, Microsoft 365 and Google Workspace for work. Each has its own accounts, login settings and logs, so each needs its own multi-factor authentication, monitoring and offboarding.

Public DNS records show that email for nikkei.co.jp, Nikkei's corporate domain, is handled by Microsoft 365. We found no sign in those records of Google Workspace being used for that domain, although that does not rule out its use under another domain. The notices do not say whether the Google Workspace account was part of a company-managed environment or a service an employee or team used on its own. If it was the latter, the company would have had less visibility, which may help explain why it took a notification from Google to find the breach.

What this means for readers#

  • If you exchanged emails with Nikkei staff and received an unexpected message from them around September 30, 2026, especially one with a link, do not open the link. If you entered a password after clicking, change it immediately, and anywhere else you used it.
  • Expect more impersonation. Nikkei warns that emails pretending to be from its staff or group companies may increase. Check through another channel before acting on unusual requests, and report suspicious emails through Nikkei's inquiry form.
  • If your organization relies on cloud mail and chat, treat account takeover as a standing risk: require phishing-resistant multi-factor authentication, revoke sessions as well as resetting passwords after an incident, and watch for unusual outbound mail from user accounts.

Japanese terms at a glance#

Japanese Reading Meaning
日本経済新聞社 Nihon Keizai Shimbunsha Nikkei Inc.
不正ログイン fusei roguin Unauthorized login
なりすましメール narisumashi mēru Impersonation email
悪性サイト akusei saito Malicious website
取材先 shuzaisaki News source, interviewee
個人情報保護委員会 Kojin Jōhō Hogo Iinkai Personal Information Protection Commission

We will update this article if Nikkei publishes the number of people affected by the Microsoft 365 breach or more on the cause.