Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Nikkei disclosed two separate employee cloud-account incidents in October 2026. One compromised Microsoft 365 account sent roughly 9,000 phishing emails, including to journalistic sources and other people who had previously communicated with Nikkei employees. A separate Google Workspace account incident may have exposed information associated with 1,646 people, but Nikkei said that data did not include reader or journalistic-source information.

What happened in the two Nikkei account incidents?

The incidents involved different employee accounts and services. The Record reported on October 5, 2026, that Nikkei disclosed them on October 4. The reporting does not establish that they were connected.

Incident Reported timeframe What happened Reported data scope
Microsoft 365 Phishing sent September 30, 2026 An unauthorized party accessed an employee account and used it to send roughly 9,000 emails containing links to malicious websites. Recipients included journalistic sources and people who had previously communicated with Nikkei employees. Names and email addresses of recipients, and the contents of some emails, may have been exposed. The number of people whose personal information may have been compromised was still being determined.
Google Workspace Unauthorized access reportedly began in late July 2026; Nikkei learned of it in early August after a Google alert. An employee account was accessed without authorization. Information associated with 1,646 employees, business partners, and others may have been exposed. Nikkei said it did not include reader or journalistic-source information.

These figures and details are reported by The Record; ITmedia also reported the two services and the main figures in its October 5, 2026 coverage.

How did the Microsoft 365 incident affect journalistic sources?

The compromised account was used to send phishing messages to people inside and outside Nikkei. Because journalistic sources were among the recipients, the incident created a direct impersonation risk for people who might reasonably expect to receive email from Nikkei employees. The reported potential exposure also included recipients’ names, email addresses, and the contents of some emails; the reports do not establish that every recipient’s correspondence was accessed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Nikkei said it changed the account password, detected no further unauthorized access, contacted recipients, and asked them to delete the malicious emails. It reported the incident to Japan’s data-protection authority. The final count of people whose personal information may have been compromised was not yet established in The Record’s report.

What was different about the Google Workspace incident?

The Google Workspace incident was a separate account intrusion, reportedly beginning in late July. The potentially exposed information related to 1,646 employees, business partners, and others. Nikkei said this dataset did not include reader or journalistic-source information, so it should not be conflated with the Microsoft 365 phishing incident that reached journalistic sources.

Nikkei reportedly changed the Google Workspace account password and said there were no later unauthorized logins or evidence that the potentially exposed information had been misused.

What should recipients do with a suspicious Nikkei email?

Nikkei warned, “There may be an increase in emails impersonating Nikkei employees or our group companies,” according to The Record’s account of the company’s statement.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Do not click links or open attachments in an unexpected message, even if the sender appears to be a Nikkei employee or group company.
  • Verify unusual requests through a separate, previously trusted contact method rather than replying to the message or using its links.
  • If you received one of the incident emails, follow Nikkei’s request to delete it. If you already clicked a link or entered account details, contact your organization’s IT or security team promptly and change any exposed password through the legitimate service.

What remains unknown?

The reports do not identify an attacker, explain how either account was initially accessed, or say whether multifactor authentication was enabled. They also do not establish whether the incidents were related or whether any recipient clicked a malicious link. The disclosure therefore supports describing a phishing campaign and possible data exposure, but not claiming a confirmed malware infection, a specific credential-theft technique, or misuse of the exposed information.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How does this compare with Nikkei’s 2025 Slack incident?

The October 2026 incidents are distinct from a Slack incident disclosed in November 2025. The Record reported that names, email addresses, or chat histories of more than 17,000 employees and business partners may have been exposed in that earlier incident. That figure concerns the separate Slack event, not the two October 2026 cloud-account incidents.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.