Nikkei Reports Email Account Breaches Used for Phishing Campaigns
Compromised Microsoft 365 and Google Workspace accounts used to send thousands of phishing emails

Key Takeaways
- Nikkei disclosed breach of two employee email accounts (Microsoft 365 and Google Workspace).
- One compromised account was used to send thousands of phishing emails.
- The exact method of initial access and attacker identity are currently unknown.
- No patch is available; immediate password resets and MFA enforcement are recommended.
- Recipients should remain vigilant for phishing emails and verify sender authenticity.
Quick answers
- What happened?
- Japanese publishing giant Nikkei has disclosed that unknown attackers breached two employee email accounts, utilizing one of the accounts to dispatch thousands of phishing emails. The incident underscores the ongoing risk of email account compromise and its potential use in credential theft and malware distribution campaigns.
- Which products are affected?
- Microsoft 365, Google Workspace
- What should defenders do?
- Affected organizations should immediately reset passwords, enforce multi-factor authentication, investigate mailbox rules and forwarding settings, and conduct thorough forensic analysis of the compromised accounts. Users should verify the authenticity of unexpected emails and report suspicious messages.
Japanese publishing giant Nikkei announced over the weekend that unknown attackers had breached two employee email accounts. According to the disclosure, one of the compromised accounts was used to send thousands of phishing emails. The breached accounts were associated with Microsoft 365 and Google Workspace platforms. The exact method of initial access remains unspecified in the current reporting. Nikkei has not detailed the specific data exfiltrated or the number of recipients successfully targeted. The incident highlights the potential for compromised email accounts to serve as vectors for large-scale phishing campaigns, posing risks of credential theft and malware installation for recipients. BleepingComputer reported the disclosure, noting that further investigation is needed to determine attacker identity and the full scope of the impact.
Security Details
Compromised Microsoft 365 and Google Workspace accounts used to send thousands of phishing emails. Exact initial access vector and attacker identity are unconfirmed.
Affected products
Microsoft 365, Google Workspace
Mitigation
Affected organizations should immediately reset passwords, enforce multi-factor authentication, investigate mailbox rules and forwarding settings, and conduct thorough forensic analysis of the compromised accounts. Users should verify the authenticity of unexpected emails and report suspicious messages.
Sources
BleepingComputer
Nikkei discloses breaches of employees’ Microsoft, Google email accounts
Oct 6, 2026 · 09:25
Original link
Related Security News

FBI Removes Accenture Contractor Following ShinyHunters-Linked Breach
The U.S. Federal Bureau of Investigation has removed an Accenture contractor from its systems, citing an alleged security failure related to patch management in connection with a breach linked to the threat actor ShinyHunters. The incident resulted in the theft of personal details of thousands of FBI employees. Reuters reported the development, citing sources familiar with the matter.




