HomeRisk ManagementsNikkei Reports Two Compromised Employee Cloud Accounts

Nikkei Reports Two Compromised Employee Cloud Accounts

Published on

spot_img

Unauthorized Access at Nikkei: Phishing Incident and Data Compromise

In a troubling incident for the prominent Japanese media conglomerate Nikkei, the organization has confirmed that unauthorized access to two employee cloud accounts has taken place. This alarming breach included one account that was exploited to send approximately 9,000 phishing emails to both staff members and external contacts whom its journalists had interacted with.

Nikkei released a statement on October 4, detailing that an employee’s Google Workspace account had been compromised since late July. This unauthorized access has potentially exposed the names and email addresses of 1,646 individuals, including employees, business partners, and other associates of the company. The announcement underscored the gravity of the situation, which was first brought to the company’s attention in early August through a notification from Google. Following the alert, Nikkei took swift action, changing the compromised account’s password immediately. Fortunately, since that time, the company has not detected any further unauthorized logins, and it has not confirmed any additional harm stemming from the breach.

Importantly, Nikkei clarified that the information that was exposed does not include details regarding its readers or news sources, which is a significant aspect given the sensitive nature of journalistic integrity. In compliance with regulatory requirements, the company reported the incident to Japan’s Personal Information Protection Commission, reflecting its commitment to transparency and accountability.

In a second revelation on the same day, Nikkei disclosed that another employee’s Microsoft 365 account had also been compromised. This security breach occurred on September 30 and facilitated the sending of around 9,000 emails that directed recipients to malicious websites. These recipients included both internal employees and contacts ensconced in various journalistic circles.

According to Nikkei, the incident involving the Microsoft 365 account may also have led to the exposure of recipients’ names and email addresses, as well as some of the content contained within the compromised emails. The company, which is actively investigating the full scope of this breach, has also taken precautionary steps by changing the account’s password. To date, it has observed no further unauthorized access attempts and has reached out individually to the recipients of the phishing emails, urging them to delete the malicious messages. Furthermore, Nikkei issued a warning to its audience about the potential for additional suspicious emails purportedly from the company or its associated entities.

Nikkei has not yet clarified how either of the compromised accounts was accessed, nor has it identified any parties behind these breaches. There remains uncertainty regarding whether the two incidents are related, leading to speculation about potential systemic vulnerabilities.

In a related occurrence, Nikkei BP, the group’s publisher, announced on October 4 that another employee’s email account had been accessed on September 30. This breach originated from credentials that were stolen via a phishing email sent from an address associated with a Nikkei employee. This incident may have put at risk the names and email addresses of 26 individuals.

These recent breaches come on the heels of a previously reported incident in November 2022, when the company disclosed that credentials stolen by infostealer malware on an employee’s personal computer were used to infiltrate its Slack workspace, compromising data pertaining to over 17,368 individuals. Moreover, in 2019, Nikkei America suffered substantial financial losses amounting to approximately $29 million due to a business email compromise scam.

In light of these security incidents, Nikkei has indicated its intention to enhance its protocols surrounding the handling of personal information and bolster defenses against unauthorized access. Such measures underscore a growing recognition of the critical importance of cybersecurity, particularly for organizations operating in a digital landscape fraught with threats. As news of these incidents circulates, it serves as a stark reminder of the challenges faced by major organizations in safeguarding sensitive data against increasingly sophisticated cyber threats.

Nikkei’s ongoing efforts to address these breaches will likely be scrutinized closely by both the public and regulatory bodies, highlighting the necessity for organizations to remain vigilant and proactive in their cybersecurity measures amidst a climate of rising digital risk.

Source link

Latest articles

Google’s Suspension of Bug Bounty Program Underscores Increasing Challenges in AI Vulnerability Triage

In the dynamic landscape of cybersecurity, experts are emphasizing the need for a critical...

Coast Guard Boardings of Hacked Vessels – New Details

US-Bound Supertankers Breached by Cyberattacks: Official Insights In a concerning development for maritime security, known...

Tenant Isolation Emerges as a Key Buying Criterion with FusionAuth’s New UK Office Opening

FusionAuth Establishes European Sales Team Amid Growing Demand for Data Control In a significant move...

Denmark Prepares for Surge in Phishing Attacks

Denmark Faces Major Data Breach, Affecting Nearly 9 Million Residents In a significant breach of...

More like this

Google’s Suspension of Bug Bounty Program Underscores Increasing Challenges in AI Vulnerability Triage

In the dynamic landscape of cybersecurity, experts are emphasizing the need for a critical...

Coast Guard Boardings of Hacked Vessels – New Details

US-Bound Supertankers Breached by Cyberattacks: Official Insights In a concerning development for maritime security, known...

Tenant Isolation Emerges as a Key Buying Criterion with FusionAuth’s New UK Office Opening

FusionAuth Establishes European Sales Team Amid Growing Demand for Data Control In a significant move...