# Nikkei discloses Microsoft 365 and Google Workspace employee account compromises; ~9,000 phishing emails sent

> Japanese media group Nikkei disclosed two separate employee-account intrusions: a Microsoft 365 account used on September 30, 2026 to send about 9,000 emails linking to malicious websites, and a Google Workspace account accessed from late July (found early August after a Google notification) that may have exposed names and email addresses of 1,646 people. No actor is attributed and any link between the incidents is undetermined.

- **Published:** 2026-10-05T00:00:00Z
- **Last reviewed:** 2026-10-05T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2952
- **ID:** TL-2026-2952
- **Severity:** MEDIUM
- **Category:** DATA_BREACH
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 4 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On October 4, 2026 Nikkei Inc. publicly disclosed two separate unauthorized-access incidents involving employee cloud accounts, as reported by The Record (published 2026-10-05) and corroborated by The Cyber Express, Alo Japan and Rankiteo.

Incident 1 - Microsoft 365: an unauthorized third party gained access to an employee's Microsoft 365 account. On September 30, 2026 the account was used to send approximately 9,000 emails containing links to malicious websites. Recipients included Nikkei staff and external parties, among them journalistic sources and contacts who had previously corresponded with employees. Exposed data comprises recipients' names, email addresses and, in some cases, email contents. Nikkei changed the account password, contacted recipients asking them to delete the messages and treat them with caution, and reported that no further unauthorized access has been detected.

Incident 2 - Google Workspace: a separate employee's Google Workspace account was accessed by an unauthorized party from late July 2026. Nikkei discovered the access in early August after a notification from Google. Names and email addresses of 1,646 people (employees and business partners) may have been exposed. Nikkei states that no reader or journalistic-source information was involved. Passwords were reset and no subsequent unauthorized access has been identified. The matter was reported to Japan's Personal Information Protection Commission; Nikkei found no evidence of misuse.

The initial access vector for both incidents (credential phishing, infostealer, MFA bypass or other) has not been disclosed, nor whether the two incidents are related. No technical indicators (sender addresses, URLs, domains, IPs, hashes) have been published, and no threat actor has been named. Context: Nikkei was previously hit by a ransomware attack on its Singapore unit (Nikkei Group Asia Pte. Ltd., May 2022) and by a Slack workspace compromise via an employee's malware-infected PC (disclosed late 2025, reportedly 17,000+ people exposed). The recurrence of account-centric intrusions against the same organization is relevant to defenders. Because the phishing mail originated from a legitimate, trusted Nikkei mailbox and targeted journalistic sources, recipients may have been especially likely to trust the links.

## MITRE ATT&CK

- T1586.002 Email Accounts
- T1078.004 Cloud Accounts
- T1566.002 Spearphishing Link
- T1534 Internal Spearphishing
- T1684.001 Impersonation
- T1114.002 Remote Email Collection

## Sources

- [Japanese media group Nikkei discloses intrusions targeting employees and users](https://therecord.media/nikkei-cyberattack-japan-data)
- [Nikkei Cyberattack: 9,000 Spoofed Emails And A Breach](https://thecyberexpress.com/nikkei-cyberattack/)
- [Nikkei Hit by Cyberattack: 9,000 Spoofing Emails Sent, Unauthorized Login to Microsoft 365 (Rankiteo)](https://blog.rankiteo.com/nikgoomic1791189711-microsoft-google-nikkei-inc-vulnerability-october-2026/)
- [Japanese media group Nikkei discloses cyberattack targeting journalistic sources (Alo Japan)](https://www.alojapan.com/1549150/japanese-media-group-nikkei-discloses-cyberattack-targeting-journalistic-sources/)
- [Nikkei M365 / Google Workspace account takeover - security notes (awaiting updates)](https://github.com/color4pen/security-notes/issues/10)
- [Media giant Nikkei reports data breach impacting 17,000 people (BleepingComputer)](https://www.bleepingcomputer.com/news/security/media-giant-nikkei-reports-data-breach-impacting-17-000-people/)
- [Unauthorized Server Access/Ransomware Incident (Nikkei Group Asia Pte. Ltd.)](https://www.nikkei.co.jp/nikkeiinfo/en/news/announcements/954.html)
- [Media giant Nikkei's Asian unit hit by ransomware attack (BleepingComputer)](https://www.bleepingcomputer.com/news/security/media-giant-nikkeis-asian-unit-hit-by-ransomware-attack/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2952
