iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Nikkei disclosed two separate employee email-account incidents on October 4, 2026: unauthorized access to an employee’s Google Workspace account beginning in late July, and a Microsoft 365 account used to send about 9,000 phishing emails on September 30. The Google incident may have exposed names and email addresses for 1,646 employees and business partners. The potential scope of data exposure in the Microsoft incident remained under investigation.
What happened in the two Nikkei email incidents?
The incidents involved different accounts, activity, timelines, and reported data exposure. Nikkei’s statements were described in reports by BleepingComputer, The Record, and INTERNET Watch.
| Incident | Reported activity and timing | Potential impact | Reported response |
|---|---|---|---|
| Google Workspace | Unauthorized access to an employee account began in late July 2026. Google notified Nikkei in early August. | Names and email addresses for 1,646 employees and business partners may have been exposed. Nikkei said readers’ and interviewees’ information was not included. | Nikkei changed the account password and reported no further unauthorized logins. |
| Microsoft 365 | An employee account sent about 9,000 emails containing links to malicious websites on September 30, 2026. | Messages went to internal staff and external contacts, including interviewees who had communicated with Nikkei employees. Names, email addresses, and some email contents may also have been exposed; the extent was still under investigation. | Nikkei changed passwords, contacted recipients individually, and asked them to delete the messages. It reported no further unauthorized logins. |
The figures were disclosed by Nikkei in 2026 as reported by the outlets above; they are incident-specific company figures, not independently audited counts. “About 9,000” is an estimate, and possible exposure does not establish that information was taken or misused.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
What information may have been exposed?
Google Workspace: a stated potential population
Nikkei said the Google account incident may have exposed names and email addresses belonging to 1,646 employees and business partners. The company said that this data did not include information about readers or interviewees.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Microsoft 365: scope not yet established
Reports said recipient names, email addresses, and some email contents may have been exposed in connection with the Microsoft incident, but the extent remained under investigation. The approximately 9,000 figure counts phishing emails sent; it is not a confirmed count of people whose information was exposed.
What should recipients of the phishing emails do?
Nikkei said it contacted recipients and asked them to delete the messages. The emails contained links to malicious websites, so recipients should not open the links or reply to the message. If you received a message claiming to be from Nikkei or one of its group companies, treat it cautiously and verify it through a separate, trusted channel rather than using contact details or links in the message. Nikkei warned that impersonation emails could increase.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
If you already opened a link or entered a password, change that password through the service’s official site or app, and change it anywhere else you reused it. If you entered financial or other sensitive details, contact the relevant provider using its independently verified contact method.
What is known about the cause and relationship between the incidents?
The reporting does not identify who accessed the accounts, how they gained access, or whether the two incidents were connected. Nikkei had not publicly attributed either incident to a specific actor. The available reports also do not establish a technical vulnerability or confirmed downstream misuse of potentially exposed information.
Rank #3
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
What did Nikkei do after the account access?
Nikkei said it changed passwords and had detected no further unauthorized logins. For the Microsoft 365 incident, the company also contacted recipients individually and asked them to delete the phishing emails. Nikkei disclosed the two incidents on October 4, 2026, following the late-July Google account access and the September 30 phishing campaign.
Quick Recap
Rank #4
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

