NIKKEI has disclosed unauthorized access to two employee cloud accounts, one of which was used to send around 9,000 phishing emails to staff and contacts. In a statement published on 4 October, the company said a Google Workspace account had been accessed from outside since late July, potentially exposing the names and email addresses of 1,646 employees, business partners and others.
Nikkei changed the account’s password promptly after learning of the access in early August, reported no further unauthorized logins, and has not confirmed any secondary harm.
In the same day’s disclosure, Nikkei said an employee Microsoft 365 account had been compromised and used on 30 September to send around 9,000 emails directing recipients to malicious websites, both inside the company and to the news sources and other contacts of several employees. The exposed recipients’ names and email addresses, and some email content, may have been exposed; the company has changed the password, detected no further logins, and is通知ing recipients to delete the messages.
Nikkei did not specify how either account was compromised or whether the two incidents are connected. Separate confirmation from Nikkei BP noted a phishing email from a Nikkei employee’s address exposed 26 names and email addresses. The disclosures follow a 2025 breach involving Slack access and a 2019 BEC loss; Nikkei said it will tighten handling of personal information and defenses against unauthorised access.