Nikkei has disclosed two separate incidents involving employee cloud accounts. An outsider logged in to a Google Workspace account from late July, and a Microsoft 365 account was used to send about 9,000 emails impersonating Nikkei staff.

Both statements are dated Oct. 4. In the Google Workspace notice, Nikkei says the account was accessed without authorisation from late July and that it learned of this in early August through a notification from Google. It changed the password at once and has seen no unauthorised logins since. Names and email addresses of 1,646 people may have been exposed. Nikkei says this does not include information about readers or news sources, and that it has confirmed no secondary harm. It reported the incident to Japan’s Personal Information Protection Commission.

The Microsoft 365 notice says an employee account came under cyber attack and that about 9,000 spoofed emails, sent on Sept. 30, went to colleagues and to news sources and other contacts of several employees. Nikkei says they led to malicious sites. Recipients’ addresses and names, and the content of some emails, may be exposed. Nikkei has reported this one to the commission, is still working out the scope, and has asked recipients individually to delete the messages. It warns that more emails impersonating Nikkei and group-company staff may follow.

Our read: the Google Workspace account was open to an outsider from late July until Google notified Nikkei in early August. Teams can ask whether their own sign-in monitoring would flag an unfamiliar login without an outside notice. The second incident shows what a compromised mailbox offers an attacker: messages from a trusted sender to people who know that employee. Impersonation campaigns such as the TA419 activity Proofpoint tracks and the Star Blizzard phishing Microsoft tracks rely on the same trust.

Source: Nikkei, notice on information leak and suspicious email sending (Microsoft 365 account)