Nikkei Says Cloud Accounts Breached, 9,000 Spoofed Emails Sent
The two disclosures show a media company's own cloud mail being used as a sending platform for impersonation, which is the part of a breach that reaches people outside the company.
Reporting from 1 source: ASCII.jp.
Nikkei Inc. said on October 4 that a Microsoft 365 account used by employees was accessed without authorization, and that about 9,000 emails impersonating employees were sent. Passwords were changed and no further unauthorized logins have been confirmed. A separate Google Workspace account was accessed from outside since late July, and the email addresses and names of 1,646 people may have leaked.
Nikkei is contacting the recipients of the roughly 9,000 impersonating emails one by one and asking them to delete the messages. The company said it changed passwords and has not confirmed any further unauthorized logins to the Microsoft 365 account.
The Google Workspace case ran longer. Access from outside began in late July and was found in early August after Google sent a notification. The names and email addresses of 1,646 people, including employees and business partners, may have leaked, and no unauthorized logins have been confirmed since the password was changed.
Synthesized by Yomimono from the 1 cited source below, including Japanese-language reporting where cited, then editorially reviewed before publishing.