Back to all lessons
Awareness Lessons
5 days ago

Nikkei Employee Email Accounts Hijacked, Used to Launch Internal Phishing Campaign

Two Nikkei employee accounts — one Google Workspace and one Microsoft 365 — were compromised by unknown attackers, exposing partner data and enabling a large-scale internal phishing campaign that reached 9,000 recipients. The core failure lies in insufficient access controls, most likely the absence of multi-factor authentication (MFA) on corporate email accounts. Once inside, attackers leveraged the trusted identity of the compromised accounts to pivot and target more victims, a classic credential abuse pattern. This incident highlights how a single weak account can become a launchpad for broader organizational harm, and why reactive measures like password resets alone are insufficient without systemic hardening.

Tactical Insight

Immediate actions

  • Enforce multi-factor authentication (MFA) on all corporate email accounts across Google Workspace and Microsoft 365 immediately.
  • Audit all active email accounts for suspicious login locations, forwarding rules, or delegated access and revoke unauthorized configurations.
  • Notify all 9,000 phishing email recipients with clear guidance on how to identify and report follow-up social engineering attempts.

Long-term improvements

  • Implement a Zero Trust access model requiring continuous verification for all SaaS applications, not just at login.
  • Establish a formal Identity and Access Management (IAM) policy with regular access reviews to detect dormant or over-privileged accounts.
  • Deploy email authentication protocols (DMARC, DKIM, SPF) to reduce the ability of compromised internal accounts to send spoofed or malicious mail at scale.

Detection measures

  • Enable SIEM or CASB integration with Google Workspace and Microsoft 365 to alert on anomalous login behavior such as impossible travel or off-hours access.
  • Set up automated alerts for bulk outbound email activity from individual accounts to catch phishing campaigns before they fully propagate.
  • Conduct regular threat-hunting exercises focused on credential compromise indicators across cloud productivity platforms.