Nikkei says cyberattack sent about 9,000 spoofed emails to sources
In short
Nikkei said on Oct. 4 that a cyberattack on a staff Microsoft 365 account let a third party send about 9,000 emails impersonating employees, including messages sent on Sept. 30 that led to malicious websites. Recipients' email addresses and names, and part of some email content, are believed to have leaked; the company changed the password, asked recipients to delete the messages and reported the case to the Personal Information Protection Commission. Asahi Shimbun also reported a separate unauthorised login to a Google Workspace account, with information on 1,646 people possibly leaked.
Read the full story 2 min read
Japan's Nikkei news publisher said on Oct. 4 that a business software account used by its employees was hit by a cyberattack and that about 9,000 emails impersonating staff were sent. [ 1 , 2 , 3 , 4 , 5 , 6 , 7 , 8 ]
According to the company, a Microsoft 365 account was accessed by a third party without authorisation. The spoofed messages, which contained content leading to malicious websites, were sent on Sept. 30 to contacts including news sources who had been in touch with several employees. Nikkei said recipients' email addresses and names, and part of the content of some emails, are believed to have leaked. The company reported the matter to the Personal Information Protection Commission and is investigating the scope of the breach and the number of personal data records involved. [ 1 , 2 , 3 , 5 , 6 , 7 ]
Nikkei said it changed the account password and asked recipients individually to delete the emails, and that no further unauthorised logins have been confirmed since. Its public relations office said: “We deeply apologise for the trouble and concern caused to those involved. We ask people to be careful of suspicious emails while we proceed with the investigation. We take this situation seriously and will further strengthen our security measures and ensure thorough information management.” [ 1 , 2 , 5 , 7 ]
Asahi Shimbun reported an additional element not mentioned by the other outlets: a cloud service “Google Workspace” account used by employees also had an unauthorised external login, and information including email addresses and names of 1,646 people may have leaked since late July. According to Asahi, that data did not include readers or news sources, no secondary damage has been confirmed, and the company learned of it in early August after being contacted by Google. [ 2 ]
Nikkei urged caution, saying more emails impersonating people at the paper and its group companies may be sent, and asking anyone who receives a suspicious message to contact it. Livedoor News and TBS NEWS DIG reported that the company is still investigating the scope of the damage and the total number of leaked personal data records. [ 1 , 3 , 4 ]
Why it matters
Nikkei is one of Japan's largest business newspapers, and the data believed to have leaked includes contact details of people outside the company, including news sources, so the incident reaches beyond its own staff. The paper says more messages impersonating its employees and group company staff may be sent, which makes its warning relevant to anyone who corresponds with it. The documents give no information on consequences for Nikkei's operations beyond the report to the Personal Information Protection Commission and the company's stated plan to strengthen security.
Key facts
- Nikkei announced on Oct. 4 that a business software account used by its employees was hit by a cyberattack and that about 9,000 emails impersonating staff were sent. [ 1 , 2 , 3 , 4 , 5 , 6 , 7 , 8 ]
- The affected software was Microsoft 365, according to the company. [ 1 , 2 , 6 , 7 ]
- The spoofed emails were sent on Sept. 30 and contained content leading to malicious websites. [ 1 , 2 , 5 , 7 ]
- Recipients' email addresses and names, and part of the content of some emails, are believed to have leaked. [ 1 , 2 , 3 , 5 , 6 , 7 , 8 ]
- Nikkei changed the account password and asked recipients individually to delete the emails, and said no further unauthorised logins have been confirmed. [ 1 , 2 , 5 , 7 ]
- Nikkei reported the matter to the Personal Information Protection Commission and is investigating the scope of the breach and the number of leaked personal data records. [ 1 , 3 , 7 ]
- Asahi Shimbun reported that a Google Workspace account used by employees was also accessed without authorisation, with information including the email addresses and names of 1,646 people possibly leaked. [ 2 ]
Confirmed by several sources
- Nikkei announced on Oct. 4 that a business software account used by employees was attacked and that about 9,000 emails impersonating staff were sent. [ 1 , 2 , 3 , 4 , 5 , 6 , 7 , 8 ]
- The spoofed emails carried content leading to malicious sites and were sent on Sept. 30. [ 1 , 2 , 5 , 7 ]
- Nikkei said recipients' email addresses and names, and part of some email content, are believed to have leaked. [ 1 , 2 , 3 , 5 , 6 , 7 , 8 ]
- Nikkei changed the password, asked recipients to delete the emails and said no new unauthorised logins have been confirmed since. [ 1 , 2 , 5 , 7 ]
- Nikkei's public relations office issued an apology and said it would strengthen security measures. [ 1 , 2 , 5 , 7 ]
- Nikkei reported the case to the Personal Information Protection Commission and is investigating the scope of the breach and the number of leaked records. [ 1 , 3 , 7 ]
Still unclear
- How many people's personal information leaked and the full scope of the breach Nikkei says it is still investigating the scope of the damage and the number of leaked personal data records, so no figure has been given.
- The reported unauthorised access to a Google Workspace account and the possible leak of information on 1,646 people This detail appears only in Asahi Shimbun's report; no other document mentions it.
- Whether the Microsoft 365 and Google Workspace incidents are connected The documents do not state any link between the two, and neither company nor the reports describe a common cause.
What local media are saying
Timeline, local time
- Nikkei announces that a staff business software account was targeted in a cyberattack and that about 9,000 spoofed emails were sent, including messages on Sept. 30 that led to malicious sites. [ 1 ]
- Asahi reports the incident and adds that a Google Workspace account was also accessed without authorisation, with information on 1,646 people possibly leaked since late July, discovered in early August after Google contacted the company. [ 2 ]
- Livedoor News and TBS NEWS DIG carry the announcement, saying the scope of the damage and the number of leaked personal data records are under investigation. [ 3 , 4 ]
- Jiji Press reports the emails went on Sept. 30 to sources who had been in contact with several employees, and that Nikkei asked recipients individually to delete them. [ 5 ]
- Sankei reports Nikkei filed a report with the Personal Information Protection Commission and that no new unauthorised logins have been confirmed after the password change. [ 7 ]
- NHK reports the incident, saying email addresses and other information are believed to have leaked. [ 8 ]