HomeSecurityNikkei: Two corporate accounts hacked

Nikkei: Two corporate accounts hacked

Japanese publishing group Nikkei has revealed new cybersecurity incidents , as unknown attackers managed to hack two employee email accounts and use one of them to send mass phishing emails . The company announced that the incidents occurred at different times and affected both employees and external contacts.

Nikkei

The first breach involved Google Workspace , which the attackers accessed in late July. The unauthorized access was discovered in early August, after the company received a notification from Google.

Personal data of 1,646 people

According to Nikkei, the account breach may have exposed the names and email addresses of about 1,646 people. The company clarified, however, that the data in question did not concern readers of its services or people who had given interviews.

See also: Ransomware at the University of Illinois Chicago – The Medical School is in the spotlight

Once the breach was discovered, Nikkei changed the password for the account in question. This action is one of the first steps in mitigating an account takeover incident, as immediate revocation of access can prevent further abuse of the account.

However, the second incident was more aggressive and had a clearly greater reach.

9,000 phishing emails from Microsoft 365 account

In September, cybercriminals managed to gain access to the Microsoft 365 of a different Nikkei employee. This time, the compromised account was used as a tool to send out around 9,000 phishing emails.

The messages were sent on September 30 to company employees, as well as to people who had previously contacted Nikkei executives in the context of interviews or other professional activities.

The emails contained links to malicious websites, creating a classic phishing scenario. Using a real corporate account significantly increases the likelihood of such a campaign being successful, as the message can appear more trustworthy than an email originating from an unknown or suspicious domain.

iPhone scams 18 phishing hero

Nikkei changed the passwords and said no new unauthorized access had been detected since then. It also contacted the recipients individually and asked them to delete the messages.

Why account takeover is so dangerous

This particular attack shows why corporate email accounts are a particularly attractive target. An account that has already been used for real business communications can provide attackers with a ready-made “channel of trust.”

See also: CPR Register Denmark: Data leak of 8.8 million people

Perpetrators don't necessarily need to create a convincing fake profile. They can send messages from a real address, mimic the tone of previous conversations, and leverage contacts or information found in the victim's mailbox.

For this reason, organizations need multi-layered protection, such as multi-factor authentication (MFA), strong access policies, suspicious connection detection, and ongoing employee training.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Warning of new attacks

Nikkei urged those who may have been affected to remain extra cautious of messages that appear to come from the company itself or its affiliates. The warning is particularly important as attackers can use data gained from a previous breach to plan more targeted attacks.

So far, the company has not attributed the incidents to a specific hacker group, and has not confirmed whether the two breaches are connected.

This is not the first cyberattack on Nikkei

The recent incidents add to a series of cybersecurity problems the group has faced in recent years. Last year, Nikkei revealed a breach of its Slack platform, affecting more than 17,000 employees and business partners

In May 2022, Nikkei Singapore suffered a ransomware attack on a server that likely contained customer data. Even more serious was an incident in 2019, when Nikkei America lost approximately $29 million in a Business Email Compromise (BEC) attack .

See also: Wikimedia Foundation reports action by OpenAI agents

Nikkei: Two corporate accounts hacked

A global group with a huge digital footprint

Nikkei is one of the world's leading media groups and owns the Financial Times and The Nikkei. It has more than 40 affiliated companies in the fields of publishing, media, events, databases and financial indices.

With dozens of international bureaus, more than 1,500 journalists and over 3.7 million digital subscriptions, the group's digital attack surface is particularly large.

Incidents show that even organizations with significant cybersecurity resources can be faced with account takeover. Protection is no longer limited to preventing an attacker from entering the network, but requires constant authentication, account monitoring and immediate response when a corporate identity is used for malicious actions.

source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS