DEV Community

Ahsan Luqman
Ahsan Luqman

Posted on Originally published at aliasfleet.com on

Nikkei Confirms Breach After 9,000 Phishing Emails Sent From Hacked Employee Account

Nikkei disclosed on October 4 that attackers had hijacked an employee's Microsoft 365 account and used it to send around 9,000 phishing emails. I run AliasFleet: one email alias per account, so a leaked address names the company that lost it. The phishing emails are what make this breach different. They went out from genuine Nikkei accounts, which means no spam filter on earth would have flagged them, and the first victim fell within days.

Two intrusions, one disclosure

Nikkei announced both incidents on October 4, as BleepingComputer reports. The facts, from the company's own statements:

Incident What happened Data at risk
Microsoft 365 (September) An employee's account was accessed by an unauthorised third party; on September 30 the hijacked account sent ~9,000 emails with links to malicious websites to staff and external interviewees and contacts Recipients' names, email addresses, and in some cases email contents
Google Workspace (July onward) A separate employee's account was accessed without authorisation from late July; Nikkei found out in early August after a notification from Google Names and email addresses of 1,646 employees and business partners

"On September 30th, emails containing links to malicious websites were sent to internal staff and to interviewees with whom several employees had been in contact. Our company has changed its passwords, and no unauthorized logins have been confirmed since then. We have contacted the recipients individually and requested that they delete the emails." (Nikkei's statement, October 4)

Nikkei says no reader or journalistic-source information was caught in the Google Workspace intrusion, and it has reported both incidents to Japan's Personal Information Protection Commission, The Cyber Express reports. Who ran the attacks, and whether the two are connected, is unknown.

The trusted domain is the whole attack

Most phishing fails at the first hurdle: the sender looks wrong. A message from nikkei-support-security.net raises eyebrows. A message from an actual Nikkei employee's account raises none. That is what the attackers bought with this intrusion. The 9,000 emails did not need to look convincing, because the envelope did the convincing.

This is the inversion of the usual breach story. Normally a breach hands attackers a list of addresses, and the phishing comes later from spoofed domains. Here the breach handed the attackers the sending identity itself. The recipients were journalists' sources and past correspondents, people with every reason to open an email from a Nikkei reporter. Threadlinqs, which catalogued the disclosure, notes the obvious: because the phishing mail originated from a legitimate, trusted Nikkei mailbox, recipients were especially likely to trust the links.

Nikkei's own warning says the same thing in plainer terms. The company told affected people to watch for suspicious emails impersonating Nikkei or its subsidiaries. The impersonation has already started, because the first wave was not impersonation at all. It was the real account.

It worked within days: the Nikkei BP case

Here is the detail that turns this from a cautionary tale into a confirmed one. INTERNET Watch reports that Nikkei BP, a separate group company, disclosed its own breach on October 4. An employee there received one of the phishing emails, the one that arrived from a Nikkei employee's genuine address, and entered their credentials. The attackers got in. Twenty-six personal records, names and email addresses, may have leaked before the account was shut down.

One of the 9,000 emails worked. That is all it takes. Nikkei BP was notified, its people were contacted, and the account was blocked fast. But the chain is complete and documented: trusted domain, opened email, stolen credentials, second breach. When a security team writes "be suspicious of messages from trusted senders," this is the week they will cite.


The attackers now know two things: that @nikkei.com addresses get opened, and that the recipient lists include journalists and their contacts. Expect follow-up emails that reference the breach itself, offer "security updates," or ask you to re-verify your contact details. Any message about this incident that carries a link is hostile until proven otherwise.

If you correspond with Nikkei

If you have emailed with a Nikkei reporter, editor, or staffer at any point, work from the assumption that your name and address were in the contact lists behind those 9,000 emails. Here is what to do.

  1. Find the September 30 emails and delete them. Check your spam and trash too. Do not click the links to "see what they were." The payload is the point.
  2. Assume more are coming. The attackers have the address lists and know the domain works. Any "Nikkei security update," "verify your details," or "re-confirm your subscription" email in the next month should be treated as hostile.
  3. Verify through your own channel. If a message claims to be from someone at Nikkei, reply to a thread you started, or look up their publicly listed contact and write fresh. Never follow the link in the suspicious message.
  4. Turn on multifactor authentication on your email account. The Nikkei BP employee lost credentials to a phishing page. MFA, especially a passkey, is what stops a stolen password from becoming a stolen account.
  5. Check Have I Been Pwned once the breach is listed. It is the canonical record of which addresses leaked and where, and it will notify you of future additions.

The breach-response guide walks through all of this in order.

Make the address itself the check

Here is the structural problem this breach exposes. Every piece of standard phishing advice starts with "check the sender." Nikkei just proved that check can pass and still be wrong. When the sender domain is legitimate, the advice collapses, and you are left judging tone, urgency, and plausibility, which is exactly the game the attacker wants to play.

A per-site alias changes what "check the sender" means. If the only address Nikkei ever had for you was an alias used for nothing else, then a phishing email landing on that alias narrows the suspect list to two: Nikkei, or whoever took the file. The address is the receipt, and the leak-tracing mechanism works even when the From header is genuine. An unexpected "security" email on your Nikkei alias is suspicious by construction, because you know exactly what legitimate mail on that alias looks like: the newsletter you signed up for, nothing more.

The 9,000 recipients could not do that check, because they had given Nikkei their real addresses in the course of normal correspondence. Professional correspondence is the hardest case for aliases, and it is also the case where they pay off most, because the alternative is trusting the sender field forever. If you have not used one before, this explains what an email alias is, and the set-up guide takes about two minutes.

What the investigation has not said

The honest gaps. Nikkei has not named the attacker or said whether the two intrusions are linked. The initial access method is undisclosed: credential phishing, an infostealer, or an MFA bypass are all on the table, and the company has said nothing. The exact count of phishing recipients is "about 9,000," and Nikkei has not published the sender addresses or malicious URLs, which limits what defenders can hunt for. Watch the company's own announcements for the forensic follow-up, not your inbox, because your inbox is now a contested space.

Top comments (0)