As reported by BleepingComputer, Japanese media giant Nikkei disclosed two separate employee email account compromises — one involving a Google Workspace account accessed in late July, another a Microsoft 365 account used in September to send approximately 9,000 phishing emails to staff and interviewees. Neither attack has been attributed, and Nikkei has not confirmed whether the incidents are linked.
What stands out to Shield53 analysts is not the individual incidents but the pattern. Nikkei has now disclosed at least four significant security events since 2019, including a $29 million BEC loss, a ransomware attack on its Singapore subsidiary, a Slack workspace breach affecting 17,000 individuals, and now two email account takeovers within three months of each other. This trajectory suggests a systemic gap in identity protection rather than isolated failures.
Why This Matters Beyond Nikkei
The attack chain on display here is textbook: compromise one credentialed account, use it as a trusted launching pad to phish thousands of internal and external contacts, and exploit the inherent trust recipients place in a known sender's domain. The 9,000 phishing emails sent from a legitimate Nikkei M365 account would have bypassed most email security gateways precisely because they originated from an authenticated, reputable source. SPF, DKIM, and DMARC all pass. The damage is done before any signal reaches a security tool.
The fundamental issue is that a single compromised identity in a SaaS email environment can weaponize organizational trust at scale. Traditional email security was built to stop messages from outside the perimeter — not from a colleague three desks away.
Who Is Most at Risk
- Media and publishing organizations — high-profile brands with large contact lists of sources, interviewees, and partners whose trust can be exploited
- Organizations with journalists or executives who communicate with sensitive contacts — a compromised reporter's account can expose whistleblower identities, source relationships, and unpublished story material
- Companies with partial MFA coverage — if even 5% of accounts lack strong authentication, that's the attack surface
- Enterprises relying on native email security without supplemental behavioral analytics — Microsoft and Google's built-in protections are necessary but insufficient against account-takeover-driven phishing
The Deeper Implication: Repeated Compromise Signals Governance Failure
When an organization experiences repeated credential-based compromises across different platforms — Slack, Google Workspace, Microsoft 365 — over several years, the common denominator is not the platform. It's the identity lifecycle. Nikkei's history suggests gaps in one or more of: privileged access management, conditional access policy enforcement, session token monitoring, and post-incident remediation depth. Changing a password after discovering a breach, as Nikkei did in both cases, is table stakes — not a remediation strategy. Attackers who have held account access for weeks have likely established persistence through OAuth tokens, mailbox rules, or session hijacking that survives a password reset.