By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Nikkei Reports Employee Email Accounts Breached
Japanese publishing conglomerate Nikkei disclosed over the weekend that unknown attackers recently breached two employee email accounts. The breach, which occurred recently, involved unauthorized access to these accounts, with one of the compromised accounts subsequently used to send thousands of phishing emails to external recipients. The company stated that the phishing emails were sent from one of the breached accounts, indicating a sophisticated attack that leveraged legitimate credentials to distribute malicious content. Nikkei has initiated an investigation into the incident to determine the full scope of the breach and the methods employed by the attackers. The company is also working to identify the specific individuals and entities that received the phishing emails and to assess any potential impact on them. This incident highlights the ongoing threat of sophisticated cyberattacks targeting corporate networks and employee credentials. The use of compromised email accounts for phishing campaigns is a common tactic, as it allows attackers to bypass initial security filters and appear more credible to recipients. Nikkei has not yet disclosed the exact number of phishing emails sent or the specific content of those emails, but the mention of "thousands" suggests a widespread distribution effort. The investigation is expected to shed more light on the nature of the phishing campaign and any potential data exfiltration that may have occurred. The company is reportedly cooperating with cybersecurity experts to fortify its defenses and prevent future incidents. The breach underscores the critical importance of robust email security measures, including multi-factor authentication, employee training on recognizing phishing attempts, and advanced threat detection systems. Nikkei's disclosure comes amid a broader rise in cyberattacks against media organizations and other businesses, making such incidents a significant concern for corporate security. The company has committed to providing further updates as its investigation progresses and has begun implementing enhanced security protocols to safeguard its systems and employee data. The specific date of the breach has not been publicly disclosed, but Nikkei's announcement was made over the weekend, indicating the incident occurred shortly before the disclosure. The attackers' motive remains unclear, but phishing campaigns are often used to gather further sensitive information, deploy malware, or gain deeper access to corporate networks. The involvement of Microsoft and Google email accounts suggests the attackers may have exploited vulnerabilities or used credential stuffing techniques to gain access. Nikkei's internal systems and subscriber data are not believed to have been directly compromised in this specific incident, according to the company's initial assessment, but the investigation is ongoing to confirm this.
Original source — read the full reporting at the publisher:
Read on BleepingComputerGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.