Nikkei Employee Email Accounts Hijacked, Used to Launch Internal Phishing Campaign
Two Nikkei employee accounts — one Google Workspace and one Microsoft 365 — were compromised by unknown attackers, exposing partner data and enabling a large-scale internal phishing campaign that reached 9,000 recipients. The core failure lies in insufficient access controls, most likely the absence of multi-factor authentication (MFA) on corporate email accounts. Once inside, attackers leveraged the trusted identity of the compromised accounts to pivot and target more victims, a classic credential abuse pattern. This incident highlights how a single weak account can become a launchpad for broader organizational harm, and why reactive measures like password resets alone are insufficient without systemic hardening.
Tactical Insight
Immediate actions
- Enforce multi-factor authentication (MFA) on all corporate email accounts across Google Workspace and Microsoft 365 immediately.
- Audit all active email accounts for suspicious login locations, forwarding rules, or delegated access and revoke unauthorized configurations.
- Notify all 9,000 phishing email recipients with clear guidance on how to identify and report follow-up social engineering attempts.
Long-term improvements
- Implement a Zero Trust access model requiring continuous verification for all SaaS applications, not just at login.
- Establish a formal Identity and Access Management (IAM) policy with regular access reviews to detect dormant or over-privileged accounts.
- Deploy email authentication protocols (DMARC, DKIM, SPF) to reduce the ability of compromised internal accounts to send spoofed or malicious mail at scale.
Detection measures
- Enable SIEM or CASB integration with Google Workspace and Microsoft 365 to alert on anomalous login behavior such as impossible travel or off-hours access.
- Set up automated alerts for bulk outbound email activity from individual accounts to catch phishing campaigns before they fully propagate.
- Conduct regular threat-hunting exercises focused on credential compromise indicators across cloud productivity platforms.