Nikkei Discloses Breaches of Employee Email Accounts

Japanese publishing giant reports two separate incidents involving Google Workspace and Microsoft 365 accounts

By LineZotpaper
Published
Read Time2 min
Japanese publishing giant Nikkei has disclosed that unknown attackers breached two employee email accounts in separate incidents over the past months, exposing personal information of employees and business partners and sending thousands of phishing emails.

Over the weekend, Japanese publishing giant Nikkei disclosed that unknown attackers recently breached two employee email accounts and used one to send thousands of phishing emails.

In a Sunday statement, the company said an employee's Google Workspace account was accessed in late July, exposing the personal information of employees and business partners. Nikkei changed the account's password after discovering the breach in early August, following a notification from Google.

While this incident may have exposed the names and email addresses of 1,646 individuals, Nikkei says the affected data doesn't include information about readers or interviewees.

More recently, threat actors accessed another employee's Microsoft 365 account in September and used it to send 9,000 phishing emails targeting Nikkei staff and interviewees.

"On September 30th, emails containing links to malicious websites were sent to internal staff and to interviewees with whom several employees had been in contact," the media giant said. "Our company has changed its passwords, and no unauthorized logins have been confirmed since then. We have contacted the recipients individually and requested that they delete the emails."

The company also warned affected individuals to watch for suspicious emails that may impersonate Nikkei or its subsidiaries in new phishing attacks.

Nikkei has yet to attribute the attacks to a specific threat actor or hacking group and hasn't shared whether the two incidents are connected.

These are the latest in a string of security incidents Nikkei has disclosed in recent years. Last year, the company also revealed that its Slack messaging platform had been breached, affecting more than 17,000 employees and business partners. In May 2022, Nikkei's Singapore subsidiary was hit by a ransomware attack that affected a server "likely" containing customer data. Three years earlier, in late September 2019, Nikkei lost approximately $29 million in a business email compromise (BEC) attack that targeted a Nikkei America employee.

Nikkei owns the Financial Times and The Nikkei, the world's largest financial newspaper, and is one of the world's largest media corporations.

§

Analysis

Why This Matters

  • The breaches expose employees and business partners to potential phishing attacks and identity theft.
  • Nikkei is a major global media owner, and repeated security incidents raise concerns about its data protection practices.
  • The attacks highlight the ongoing vulnerability of email systems even in large, sophisticated organizations.

Background

Nikkei, which owns the Financial Times and The Nikkei, is one of the world's largest media corporations with over 1,500 journalists worldwide. It has experienced a series of security incidents in recent years, including a Slack breach in 2023 affecting 17,000 people, a ransomware attack on its Singapore subsidiary in 2022, and a $29 million business email compromise loss in 2019.

Key Perspectives

Nikkei: The company has disclosed the breaches, changed passwords, and contacted affected individuals. It has not attributed the attacks to any specific actor or confirmed whether the two incidents are linked. Affected individuals: Employees and business partners face potential exposure of names and email addresses and have been warned about further phishing attempts impersonating Nikkei. Security experts: The incidents underscore the persistent threat of email account compromise and the need for robust multi-factor authentication and monitoring.

What to Watch

  • Whether Nikkei identifies the attackers or establishes a connection between the two breaches.
  • If further phishing attacks targeting those affected by the breaches are reported.
  • Whether Nikkei implements additional security measures in response to this latest incident.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.