Skip to content
Rush Commerce
Software & Dev2 min read

Nikkei Microsoft 365 hack sent 9,000 phishing emails

One hijacked Microsoft 365 account at Nikkei sent about 9,000 phishing emails to staff and sources. Here's how to stop your inbox phishing your customers.

Japan's Nikkei says one employee's Microsoft 365 account was taken over, and the attacker used it to send about 9,000 phishing emails on September 30. The emails went to coworkers and to the paper's news sources, and they linked to malicious websites. One account at a large company became a phishing machine. Your business email works the same way. When it is hijacked, the attacker writes to your customers from an address they already trust.

What actually happened

Nikkei published its notice on October 5. The company believes a third party got into the account. Recipients' names and email addresses, and the content of some emails, may have leaked. Nikkei changed the password, reports no further unauthorized access, contacted recipients and asked them to delete the messages, and reported the incident to Japan's Personal Information Protection Commission.

BleepingComputer also reports an earlier compromise of a second employee's Google Workspace account in late July, which exposed the names and email addresses of 1,646 people. Neither source says how the attackers got in. Nikkei also lost Slack credentials to info-stealing malware last year, so this is not the company's first account takeover.

Why a hijacked mailbox is a customer problem

Most small businesses think of email compromise as "someone read our mail." The bigger damage is outbound. A trusted sender gets past spam filters. Your customers open it because they know you. If it asks them to "review an invoice" or "update payment details," some of them will.

Here is what we set up for every client on Microsoft 365 or Google Workspace:

  1. Phishing-resistant MFA. Passkeys or security keys, not SMS codes. Turn off legacy authentication.
  2. Outbound sending limits. Microsoft 365 lets you set outbound spam policies with per-user hourly and daily recipient limits. A normal staff account does not send 9,000 messages in a day.
  3. Alerts on mail rules and volume spikes. New forwarding rules and sudden sending bursts are the two clearest signs of takeover.
  4. A one-page response plan. Who resets the password, who revokes sessions, and who emails customers to say "ignore that message."
  5. Managed devices for anyone with admin rights. Nikkei's Slack incident started with malware on a personal computer.

Key takeaways

  • One hijacked Microsoft 365 account at Nikkei sent about 9,000 phishing emails on September 30
  • Recipient names, email addresses, and some email content may have leaked
  • BleepingComputer reports a separate Google Workspace account compromise in July
  • A taken-over mailbox phishes your customers from an address they trust
  • Use passkeys, set outbound sending limits, and alert on new mail rules

Your email tenant is part of your attack surface. We lock down Microsoft 365 and Google Workspace for small teams: MFA, sending limits, alerts, and a response plan your staff can follow. See our services, or ask us to check your tenant.

Sources: Nikkei announcement, BleepingComputer.

  • #microsoft-365
  • #phishing
  • #email-security
  • #account-takeover
  • #data-breach
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.