Nikkei Microsoft 365 account sent 9,000 phishing emails after takeover
Employee Google and Microsoft cloud mailboxes compromised

Nikkei Microsoft 365 account sent 9,000 phishing emails after takeover

Nikkei disclosed that attackers used two employee cloud accounts. One Google Workspace mailbox was opened in late July. A separate Microsoft 365 mailbox was used on 30 September 2026 to send about 9,000 phishing emails.

What happened

The company said the Google account was found in early August after a notification from Google. That access may have exposed names and email addresses of 1,646 employees and business partners. Nikkei says reader and interviewee data was not in that set.

The Microsoft 365 account was accessed in September. On 30 September, messages with links to malicious sites went to internal staff and to people Nikkei journalists had contacted, including news sources. Nikkei changed the passwords, reported the incidents to Japan's Personal Information Protection Commission, and says it has seen no further unauthorized logins. It has not named a threat actor, and it has not said whether the two breaches are connected. Some email content may also have been exposed from the Microsoft account.

Who is affected

Recipients of the 30 September wave, plus the 1,646 people whose names and addresses may have left the Google account. The practical risk is follow-on phishing that looks like it came from Nikkei or a known journalist. This is a mailbox takeover used as a sending platform, not a ransomware event.

What to do now

  • If you received a Nikkei email on or after 30 September with an unexpected link, do not open it and confirm with the sender out of band.
  • On your own tenants, review Microsoft 365 and Google Workspace sign-in logs for new countries, impossible travel, and mail rules that forward or hide messages.
  • Disable legacy authentication, require phishing-resistant MFA on mailboxes that mail external contacts, and alert when one account sends thousands of messages.
  • After a suspected takeover, revoke sessions and refresh tokens. A password change alone leaves existing sessions alive.

Source: BleepingComputer, citing Nikkei's disclosure. Nikkei discloses breaches of employees' Microsoft and Google email accounts.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

Fake ChatGPT and Gemini ad portals steal Google and Okta MFA codes
Browser-in-the-browser phishing against ad account admins