Nikkei, one of Japan's leading business media organizations, revealed on Sunday that it had suffered two distinct cyber incidents affecting employee email systems. The disclosures place the company among a wave of Japanese firms experiencing security breaches in recent weeks.

In the more severe breach, attackers gained access to a Microsoft 365 account used by a Nikkei staffer and deployed it to distribute approximately 9,000 phishing messages. Recipients included both internal staff and external contacts, notably people who serve as journalistic sources for the organization.

The malicious emails, dispatched on September 30, contained hyperlinks leading to fraudulent websites. They targeted individuals with prior communication history with Nikkei personnel. Following discovery, the company reset the compromised account's credentials and found no signs of continued unauthorized activity. Nikkei notified recipients and requested deletion of the harmful messages.

The incident may have resulted in exposure of recipient identities, email addresses, and portions of email correspondence. Nikkei reported the matter to Japan's data protection regulator and continues investigating the scope of personal data affected. "There may be an increase in emails impersonating Nikkei employees or our group companies," the company said.

The second incident involved unauthorized access to a Google Workspace account operated by a different employee beginning in late July. Nikkei identified the intrusion in early August following notification from Google and immediately changed the account password. The company has observed no further unauthorized logins and detected no evidence of misuse of the exposed information.

This breach potentially compromised personal details of 1,646 individuals, encompassing employees and business associates. Exposed data likely included names and email addresses but did not involve information pertaining to Nikkei's readership or journalistic sources, according to the company.

Nikkei has not disclosed whether the two incidents are connected or attributed either to a specific threat actor.

Broader wave of Japanese corporate breaches

Nikkei's incidents are part of a larger pattern affecting Japanese enterprises. Daiwa Securities, Japan's second-largest brokerage, announced Monday that data belonging to as many as 110,000 clients may have been taken following a breach of servers maintained by an external vendor. Daiwa emphasized that its own infrastructure remained secure and that the compromised data alone could not enable account access or transaction execution.

Additional Japanese organizations have recently reported security breaches:

  • Yamato Transport disclosed unauthorized access to a payment service supporting e-commerce transactions
  • Dai-ichi Life, an insurance provider, reported a cyber incident
  • Sagawa Express, a delivery operator, experienced unauthorized access
  • Ikegami Tsushinki, a broadcast equipment manufacturer, disclosed a breach

Nikkei's history of security incidents

Nikkei operates as one of the world's largest business media organizations. The company publishes The Nikkei financial newspaper, holds ownership of the Financial Times, maintains a workforce exceeding 3,000 personnel, and runs more than a dozen editorial offices internationally.

The organization has experienced multiple prior security events. In November 2025, Nikkei disclosed that an employee device had been compromised with malware that harvested login credentials used to breach the company's internal Slack platform. That incident potentially exposed names, email addresses, and conversation histories of more than 17,000 employees and business contacts. Nikkei stated it found no evidence that journalistic source information or reporting materials were affected.

The company's Singapore office also fell victim to a ransomware attack in 2022, which Nikkei indicated may have involved customer information.