Compromised Nikkei Microsoft 365 Account Sent About 9,000 Phishing Emails
Nikkei disclosed that an employee’s Microsoft 365 account was hijacked, resulting in roughly 9,000 phishing messages being dispatched on September 30, targeting internal and external contacts with malicious links.

On October 4, 2026, Japanese media group Nikkei announced that an employee’s Microsoft 365 account had been compromised, most likely after an unauthorized login. The breach was identified after a sudden surge of outbound messages was detected by the company’s email monitoring tools.
The compromised account was used to send approximately 9,000 emails on September 30. Each message impersonated Nikkei, addressed to a mix of internal staff and external partners, and contained links directing recipients to a malicious website designed to harvest credentials.
Scope of the Data Exposure
According to Nikkei, the attackers may have accessed the names, email addresses and a portion of the content of some of the sent messages. The company has not confirmed the full extent of the data that could have been viewed or extracted, but it acknowledges that the information was potentially exposed to the threat actors.
After detecting the unauthorized activity, Nikkei immediately reset the password of the compromised account. The firm reports that no further unauthorized logins have been observed since the password change.
Response Measures and Reporting
Nikkei reported the incident to the Japanese Personal Information Protection Commission, complying with national breach‑notification requirements. The organization is continuing its internal investigation to map the full perimeter of the attack and to determine the exact number of individuals whose data may have been compromised.
All identified recipients have been contacted individually. Nikkei asked each of them to delete the phishing emails and to remain vigilant for any follow‑up impersonation attempts, which the company warns could still occur.
Related Security Incidents
In a separate report published on October 6, 2026, iThome described a July incident affecting Google Workspace accounts belonging to 1,646 employees and partners of an unnamed organization. While iThome’s article mentions the Nikkei breach, there is no public evidence linking the two events.
- Compromise detected on September 30, 2026
- Approximately 9,000 phishing emails sent
- Password reset performed immediately after detection
- Incident reported to the Japanese Personal Information Protection Commission
- All identified recipients contacted and instructed to delete the messages
The phishing emails themselves were crafted to appear authentic, using Nikkei’s branding and familiar sender names. The malicious links embedded in the messages pointed to a domain that mimicked a legitimate service login page, a common tactic to harvest credentials from unsuspecting users.
Security experts note that Microsoft 365 accounts are attractive targets because they often have access to a wide array of corporate resources, including SharePoint, Teams, and Outlook. Once an attacker gains control of a single account, they can leverage it to launch large‑scale phishing campaigns that appear trustworthy to recipients.
For organizations that rely heavily on Microsoft 365, the Nikkei incident underscores the importance of multi‑factor authentication (MFA), continuous monitoring of login anomalies, and rapid incident response procedures. Even a single compromised credential can be weaponized to send thousands of malicious messages in a short time frame.
Concretely, English‑speaking companies should review their own email security controls in light of this breach. This includes enforcing MFA for all accounts, implementing automated alerts for bulk outbound email spikes, and conducting regular phishing simulations to keep staff aware of evolving tactics.
Prompt password changes, thorough forensic analysis, and transparent communication with affected parties remain essential steps to limit damage and restore trust after a similar compromise.
The incident also prompted Nikkei’s IT department to tighten conditional access policies, restricting third‑party app integrations that could be exploited for credential harvesting.
In the weeks following the disclosure, Tokyo‑based security firms reported a modest uptick in phishing attempts that referenced the Nikkei breach, indicating that threat actors were attempting to capitalize on the news cycle.
Overall, the event serves as a reminder that even well‑established media organizations are vulnerable to credential‑based attacks and must continuously evolve their defensive posture.
Sources
- Microsoft 365 アカウントへの不正アクセスと不審メール送信について日本経済新聞社 · October 4, 2026
- 日經M365帳號遭駭,約9千封釣魚郵件被寄出iThome · October 6, 2026



