TechRadar News.
Technology

Nikkei Acknowledges Email Account Compromise, Mass Phishing Campaign Launched

Nikkei Acknowledges Email Account Compromise, Mass Phishing Campaign Launched

Over the weekend, Japanese media group Nikkei disclosed that an unknown threat actor had breached the Microsoft and Google email accounts of two staff members, with one of the compromised accounts subsequently employed to send a massive number of phishing messages.

According to the firm, the breach came to light when its security monitoring systems flagged abnormal outbound traffic. investigators concluded that the perpetrators obtained the credentials, though they have not revealed whether the theft resulted from phishing, credential stuffing, or another approach.

After gaining entry, the attackers used one of the hijacked accounts to dispatch thousands of counterfeit emails to outside contacts. These phishing messages were said to imitate authentic business communications, seeking to tempt recipients into clicking harmful links or surrendering additional credentials. While Nikkei did not disclose the exact number of targets, it stressed that the operation was stopped promptly once identified.

Security specialists point out that corporate email addresses continue to be a favored conduit for mass phishing campaigns due to the trust they inherently command. A message appearing to come from a legitimate address boosts the likelihood that recipients will interact with it, thereby raising the odds of credential theft or malware infection. This episode highlights the persistent difficulty firms face in safeguarding cloud‑based email platforms, even with multifactor authentication deployed.

In its communiqué, Nikkei affirmed that neither confidential editorial content nor subscriber information seems to have been accessed or removed. The company is working alongside law‑enforcement agencies and external security consultants to identify the breach’s origin and to bolster its safeguards. It also urged customers and partners to stay alert for any dubious emails that might have been sent from the compromised accounts.

This intrusion joins a growing series of assaults on Japanese companies observed in recent months, with threat actors focusing on high‑profile targets to magnify the reach of their phishing efforts. Analysts anticipate that Nikkei and its peers will reassess and likely tighten access controls, broaden staff security training, and implement more sophisticated email authentication measures—including DMARC, DKIM and SPF—to counter comparable threats ahead.

TechRadar Desk — Editorial desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related