Nikkei said a compromised Microsoft 365 account sent roughly 9,000 phishing emails to people who had previously corresponded with its employees, including journalistic sources. The company said the messages went out on September 30 and may have exposed recipients’ names, email addresses, and some email contents.
The attack worked because it came from a real employee mailbox, not a spoofed sender. That made the messages look like ordinary follow-up mail and gave the links more credibility, while also putting the mailbox’s existing contact history and prior conversations into the exposure set.
For newsrooms and any organization whose staff exchange email with outside partners, the blast radius is everyone in the sender’s contact graph, not just the account itself. Nikkei also disclosed a separate Google Workspace intrusion, and it has not said whether the two incidents are connected.
Nikkei discloses breaches of employees’ Microsoft, Google email accounts
Over the weekend, Japanese publishing giant Nikkei disclosed that unknown attackers recently breached two employee email accounts and used one to send thousands of phishing emails.