Nikkei Microsoft Account Compromise Sends Thousands of Phishing Emails
A corporate Microsoft 365 account belonging to an employee at the Japanese newspaper publisher Nikkei was compromised by hackers, resulting in the unauthorized transmission of approximately 9,000 phishing emails, ithome.com reported. The security breach prompted immediate mitigation steps from the media company, which stated that no further illegal login attempts have been detected since the affected employee updated their account credentials.
The malicious emails directed recipients to visit external websites controlled by the attackers. In response to the incident, Nikkei initiated direct contact with the individuals who received the messages, instructing them to delete the fraudulent communications immediately. The organization also notified the Personal Information Protection Commission of Japan regarding the breach.
Nikkei investigates incident and warns of further phishing
Nikkei is actively investigating the scope of the incident to determine how many individuals received the messages and whether any personal information was exposed during the unauthorized access.
The publisher issued a public warning advising that malicious actors may continue to impersonate Nikkei employees and staff from group companies in subsequent phishing campaigns. For anyone who receives suspicious correspondence, the company recommends utilizing official inquiry forms on its corporate website to verify authenticity before interacting with any links or attachments.
Frequently Asked Questions About the Nikkei Phishing Incident
When did Nikkei disclose the Microsoft 365 account breach?
The Japanese economic newspaper published its official notice regarding the security breach on October 4, detailing the unauthorized access to a single employee’s corporate account.
How many phishing emails were sent from the compromised account?
Hackers used the breached Microsoft 365 credential to send approximately 9,000 deceptive emails to outside recipients, directing them to access malicious websites.
Which regulatory body received notification of the security incident?
Nikkei formally reported the unauthorized access and potential data exposure scope to the Personal Information Protection Commission of Japan.
Worth a look