VYPR
breachPublished Oct 5, 2026· 1 source

Nikkei Discloses Cyberattack Targeting Journalistic Sources

Japanese media group Nikkei has reported a cyberattack that compromised an employee email account, potentially exposing sensitive information related to journalistic sources.

Japanese media conglomerate Nikkei has disclosed two separate cyber incidents that involved the compromise of employee email accounts, adding to a recent surge of data breaches affecting major Japanese corporations. The more recent incident, which occurred on September 30, saw an attacker gain unauthorized access to a Microsoft 365 account belonging to a Nikkei employee. This compromised account was subsequently used to distribute approximately 9,000 phishing emails to both internal and external recipients, critically including individuals who had previously communicated with Nikkei employees.

The phishing emails contained malicious links designed to redirect recipients to harmful websites. Nikkei stated that it has since secured the compromised account by changing its password and has not detected any further unauthorized access. The company has also reached out to affected recipients, urging them to delete the deceptive messages. The potential exposure includes recipients' names and email addresses, and possibly the content of some emails, raising concerns about the confidentiality of journalistic sources.

Nikkei has formally reported this incident to Japan's data protection authority and is currently undertaking an investigation to ascertain the full extent of personal information compromised. The company has cautioned that there may be an increase in emails impersonating Nikkei employees or its group companies, urging vigilance among its contacts.

In a separate disclosure made on the same day, Nikkei revealed that a Google Workspace account used by another employee had been accessed without authorization starting in late July. This earlier breach potentially exposed personal information belonging to 1,646 individuals, including employees and business partners. Nikkei became aware of this intrusion in early August after receiving an alert from Google and promptly changed the account password.

While Nikkei has confirmed no subsequent unauthorized logins and found no evidence of misuse of the exposed data from the Google Workspace incident, the compromised information may have included names and email addresses. Crucially, Nikkei stated that this breach did not affect information related to its readers or journalistic sources. The company has not yet indicated whether these two incidents are connected or attributed them to any specific threat actor.

These disclosures follow a pattern of escalating cyber incidents impacting Japanese companies. Recent weeks have seen major firms like Daiwa Securities, Yamato Transport, Dai-ichi Life, Sagawa Express, and Ikegami Tsushinki report various cyberattacks and data breaches, highlighting a growing cybersecurity challenge within the nation's corporate sector.

Nikkei, a globally recognized business media entity, has a history of cyber incidents. In November 2025, a malware infection on an employee's computer led to the theft of credentials, which were then used to access the company's internal Slack application, potentially exposing data for over 17,000 individuals. More recently, in 2022, Nikkei's Singapore headquarters fell victim to a ransomware attack that may have involved customer data.

The current incidents underscore the persistent threat to sensitive data, particularly concerning journalistic sources, and the broader vulnerability of major organizations to sophisticated cyberattacks. The lack of attribution in these cases leaves open questions about the actors behind these intrusions and their motivations.

Synthesized by Vypr AI