The news
Nikkei Inc., the Japanese media group that publishes the Nikkei business newspaper, said on October 5, 2026 that a Microsoft 365 email account belonging to one of its employees was compromised and used to send about 9,000 spoofed emails. In its notice, the company said the Nikkei email hack was discovered on September 30.
According to Nikkei, the leaked information includes recipients' names and email addresses and the content of some emails. The recipients were contacts inside and outside the company, including news sources and others who had previously exchanged email with several Nikkei employees.
Nikkei said it changed the affected account's password, contacted recipients individually to ask them to delete the messages, and reported the incident to Japan's Personal Information Protection Commission. It said it is investigating the scope of the breach, apologized, and pledged to strengthen security and information management.
The Record, a cybersecurity news outlet, reported that Nikkei detected no further unauthorized access after the password change and warned that emails impersonating its employees or group companies may increase. The Record also reported that neither this incident nor an earlier one had been attributed to a specific hacking group.
This is not Nikkei's first email security incident. The Record reported that unauthorized access to a Google Workspace environment beginning in late July 2026 affected 1,646 employees and business partners, exposing names and email addresses but not reader or source information. Nikkei separately disclosed in May 2026 that a Microsoft 365 account at its U.S. subsidiary, Nikkei America, had been accessed without authorization.
The numbers
- Spoofed emails sent
- About 9,000
- Date discovered
- September 30, 2026
- People affected in earlier Google Workspace intrusion
- 1,646
Why CEOs should care
For a news organization, the identity of a source is among the most sensitive information it holds. Nikkei's case shows how a single compromised mailbox can expose not just one person's messages but a map of who the company talks to. Every business has an equivalent: deal advisers at a bank, patients at a clinic, whistleblowers at a compliance team, acquisition targets in a CEO's inbox.
For CISOs, the action items are concrete. Identify the mailboxes whose contact lists or contents would be most damaging if exposed, such as executives, legal, M&A, investor relations and newsroom staff, and give them phishing-resistant multi-factor authentication like hardware security keys, conditional access rules and alerts on mass outbound sending. A 9,000-message burst from one account is the kind of anomaly that automated controls can flag or block.
For boards and general counsel, ask how fast the company could notify affected contacts and regulators, as Nikkei did with Japan's privacy commission, and whether the incident response plan covers the reputational harm to partners whose details leak, not just the company's own data.
The bigger picture
Attackers increasingly use a trusted account to phish that account's contacts, because emails from a real colleague or reporter are far more convincing than cold messages. The Record's account of repeated incidents at Nikkei, across both Microsoft 365 and Google Workspace, suggests cloud email accounts remain a persistent weak point even at large, security-aware organizations.
What’s next
Nikkei said its investigation into the breach's scope continues, so watch for an update on how many people's information was affected. Recipients should be wary of follow-on emails impersonating Nikkei staff, which the company warned may increase.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error
Companies in this story








