Japanese publishing company Nikkei says unknown attackers recently breach two employees’ cloud email accounts. According to Nikkei, the attackers accessed Microsoft and Google email accounts and used one account to send thousands of phishing messages.
The disclosure comes after the company identified suspicious activity and notified relevant parties. One source reports that the compromised account is used to send about 9,000 phishing emails, while the other describes the activity more generally as “thousands” of phishing emails. Both accounts characterize the incidents as targeted compromises of employee credentials rather than a broader system-wide breach, though details on scope and impact beyond email activity are limited.
Different outlets focus on the same core facts: Nikkei confirms two employee account compromises, one account is linked to large-volume phishing, and the activity is attributed to unidentified attackers. Public reporting does not include specific information on who the attackers are, how the accounts were accessed, or what measures Nikkei has taken in response beyond the disclosure itself.