Japanese media group Nikkei discloses cyberattack targeting journalistic sources
What happened
The Japanese media giant Nikkei disclosed a cyber incident involving an employee email account that may have compromised journalistic sources. Nikkei said it changed the password for the compromised account and has detected no further unauthorized access.
Nikkei discovered the intrusion in early August after receiving an alert from Google and changed the account password. In the more recent incident, an attacker compromised a Microsoft 365 account belonging to a Nikkei employee and used it to send roughly 9,000 phishing emails to people inside and outside the company, including journalistic sources.
The emails sent on September 30 contained links directing recipients to malicious websites and targeted people who had previously communicated with Nikkei employees, the company said. It also contacted recipients and asked them to delete the malicious messages.
The breach may have exposed recipients' names and email addresses, as well as the contents of some emails. Nikkei said it reported the incident to Japan's data protection authority and is still determining how many people had their personal information compromised.
Sources & evidence
- The Record Reporting source
Japanese media group Nikkei discloses intrusions targeting employees and users โ
https://therecord.media/nikkei-cyberattack-japan-data