As reported by BleepingComputer, Japanese media giant Nikkei disclosed two separate employee email account compromises — one involving a Google Workspace account accessed in late July, another a Microsoft 365 account used in September to send approximately 9,000 phishing emails to staff and interviewees. Neither attack has been attributed, and Nikkei has not confirmed whether the incidents are linked.

Key Takeaway: As reported by BleepingComputer, Japanese media giant Nikkei disclosed two separate employee email account compromises — one involving a Google Workspace account accessed in late July, another a Microsoft 365 account used in September to send approximately 9,000 phishing emails to staff and interviewees.

What stands out to Shield53 analysts is not the individual incidents but the pattern. Nikkei has now disclosed at least four significant security events since 2019, including a $29 million BEC loss, a ransomware attack on its Singapore subsidiary, a Slack workspace breach affecting 17,000 individuals, and now two email account takeovers within three months of each other. This trajectory suggests a systemic gap in identity protection rather than isolated failures.

Why This Matters Beyond Nikkei

The attack chain on display here is textbook: compromise one credentialed account, use it as a trusted launching pad to phish thousands of internal and external contacts, and exploit the inherent trust recipients place in a known sender's domain. The 9,000 phishing emails sent from a legitimate Nikkei M365 account would have bypassed most email security gateways precisely because they originated from an authenticated, reputable source. SPF, DKIM, and DMARC all pass. The damage is done before any signal reaches a security tool.

The fundamental issue is that a single compromised identity in a SaaS email environment can weaponize organizational trust at scale. Traditional email security was built to stop messages from outside the perimeter — not from a colleague three desks away.

Who Is Most at Risk

  • Media and publishing organizations — high-profile brands with large contact lists of sources, interviewees, and partners whose trust can be exploited
  • Organizations with journalists or executives who communicate with sensitive contacts — a compromised reporter's account can expose whistleblower identities, source relationships, and unpublished story material
  • Companies with partial MFA coverage — if even 5% of accounts lack strong authentication, that's the attack surface
  • Enterprises relying on native email security without supplemental behavioral analytics — Microsoft and Google's built-in protections are necessary but insufficient against account-takeover-driven phishing

The Deeper Implication: Repeated Compromise Signals Governance Failure

When an organization experiences repeated credential-based compromises across different platforms — Slack, Google Workspace, Microsoft 365 — over several years, the common denominator is not the platform. It's the identity lifecycle. Nikkei's history suggests gaps in one or more of: privileged access management, conditional access policy enforcement, session token monitoring, and post-incident remediation depth. Changing a password after discovering a breach, as Nikkei did in both cases, is table stakes — not a remediation strategy. Attackers who have held account access for weeks have likely established persistence through OAuth tokens, mailbox rules, or session hijacking that survives a password reset.

Shield53 Recommendations

Shield53 Recommendations
Enforce phishing-resistant MFA universally — FIDO2/WebAuthn keys or platform authenticators. SMS and TOTP are bypassable via SIM swapping and MFA fatigue attacks. No exceptions for any account, including shared mailboxes and service accounts.
Implement conditional access policies that block or require step-up authentication for impossible travel, new device sign-ins, and access from unmanaged devices. Both Microsoft and Google support these natively.
Deploy account-takeover detection — monitor for anomalous mailbox activity: sudden spikes in sent email volume, creation of inbox forwarding rules, OAuth app grants, and access from unfamiliar geographies. Tools like Microsoft Defender for Office 365 or Google's security center provide these signals, but they must be tuned and alerting must be operationalized.
Revoke all active sessions and OAuth tokens after any confirmed account compromise — not just password resets. A password change alone does not invalidate existing session tokens or malicious app consents.
Audit mailbox rules and OAuth app grants quarterly — attackers frequently create hidden forwarding rules or grant API access to malicious applications that persist long after the initial compromise is "contained."
Conduct a full identity posture review if your organization has experienced more than one credential-based incident in 24 months. The pattern is telling you something about your architecture, not your users.
Implement outbound phishing detection — most email security stacks focus exclusively on inbound. The Nikkei incident demonstrates that outbound phishing from a compromised internal account is the higher-impact threat for trusted brands.