Read summarized version with

Key takeaways
- Nikkei disclosed two separate incidents: a compromised Microsoft 365 account sent about 9,000 phishing emails on September 30 impersonating staff, and a separate Google Workspace account was accessed without authorization from late July until Google alerted Nikkei in August, exposing information tied to 1,646 employees and business partners.
- The article ties both events to compromised credentials and frames the phishing blast as “lateral phishing,” citing a peer-reviewed study of 113 million enterprise emails by University of Chicago researcher Grant Ho and Columbia University’s Asaf Cidon on how attackers exploit trust and information inside hijacked accounts.
- A key lesson is that prevention and detection are distinct jobs: message-level detection should catch unusual content, tone, timing, and sending volume, while identity controls such as MFA, login anomaly detection, OAuth app review, and conditional access are needed to catch unauthorized account access earlier.
- Nikkei’s response is presented as a model: it reset passwords quickly, notified affected people directly, reported both incidents to Japan’s data protection authority, and said it had found no evidence so far of further misuse of the exposed information.
- The piece cites Carnegie Mellon CyLab director Dr. Lorrie Cranor’s view that training should be a last resort behind strong systems, and Columbia professor Asaf Cidon’s warning that modern phishing emails can be polished and professional, making compromised trusted accounts especially hard for users to spot.
- For practical defense, the article recommends monitoring high-trust accounts for unusual sending patterns, regularly reviewing login and OAuth activity, preparing pre-written incident communications, and using realistic phishing simulations; it also cites Grant Ho’s eight-month study of 19,500 employees showing generic annual training barely helped, while interactive scenario-based training cut phishing failure rates by 19% among participants.
A journalist builds a career on one asset above all others: the trust of the people willing to talk to them. A source picks up the phone because they recognize the name on the screen. A business partner opens an email because the sender address looks familiar. That trust took years to build. It can be borrowed by an attacker in seconds.
Nikkei disclosed two separate email security incidents this past week, laid out in detail in the company’s own public statement. Few newsrooms carry the kind of institutional trust Nikkei has built over more than a century. That is exactly why the pattern behind these incidents is worth studying closely, whatever size or industry the reader runs.
What Happened, in Plain Terms
Here is the sequence, based on Nikkei’s disclosure. A compromised Microsoft 365 account sent roughly 9,000 phishing emails on September 30. The messages impersonated Nikkei staff and targeted journalistic sources, the exact people whose trust the organization depends on most.
A second, separate incident involved a Google Workspace account. Unauthorized access began in late July. Nikkei discovered it in August, through a security alert from Google itself. Information connected to 1,646 people, employees and business partners, was exposed.
Both incidents trace back to the same root cause: a compromised credential, used differently each time.
Why This Pattern Reaches Far Beyond One Newsroom
Attackers rarely need to breach a core system to cause damage. A compromised email account becomes a megaphone on its own. It borrows the credibility an organization spent years earning, then points that credibility directly at the people who trust it most: customers, partners, sources, employees.Researchers have a name for exactly this pattern: lateral phishing. Grant Ho of the University of Chicago led a peer-reviewed study of 113 million enterprise emails, with Columbia University’s Asaf Cidon among the co-authors. Their finding explains why these attacks work so well: adversaries leverage “both the implicit trust and the information in the hijacked user’s account.” That single sentence describes the mechanism behind the Nikkei phishing blast almost exactly.
Weeks passed between the Google Workspace intrusion and its discovery. That gap is the second lesson here. Prevention matters. Detection speed matters just as much, and it depends on watching the right signal. Catching a hijacked account sending thousands of impersonation emails is a content and behavior problem. Catching unauthorized access to that account in the first place is an identity and access problem, generally caught by login anomaly detection, OAuth app review, and conditional access policies rather than by anything reading message content. Organizations that close this gap fastest tend to be the ones treating both as connected but distinct jobs, rather than expecting one tool to do both.
How Nikkei Responded
Credit belongs where it is due. Nikkei reset passwords quickly. The company contacted the people affected directly, rather than letting the news reach them secondhand. It reported both incidents to Japan’s data protection authority. As of this writing, Nikkei states it has found no evidence that the exposed information led to further misuse, a reasonable and responsible finding to report, and also the kind of assessment worth revisiting as more information comes in rather than treating as a final word.
This is what a healthy response looks like. Incidents are manageable when they are caught, disclosed clearly, and handled without delay. That is a template worth repeating.
Turning the Lesson Into Action
A compromised, trusted account turned against the very people who rely on it is one of the hardest scenarios to defend against with technology working alone. People are the last line of defense in a moment like this, and they deserve to be equipped for it rather than blamed when it slips past them.
Dr. Lorrie Cranor, director of Carnegie Mellon University’s CyLab Security and Privacy Institute, has spent years studying where security puts too much weight on individual judgment. Her view is direct: “Ideally, training and education are the last resort.” The systems should carry the heaviest part of the load. People should only need to step in for what technology genuinely cannot catch on its own.
That is the combined approach worth building toward, and it has three parts, each covering a different piece of what happened at Nikkei.
Content and impersonation detection should read the full context of a message, not just scan for known bad links, so that an email sent from a hijacked but technically legitimate account still gets flagged on tone, timing, and intent. This is the piece Adaptive’s agentic email security is built for: analyzing messages in context and watching for the kind of unusual sending volume and pattern that marked the Nikkei phishing blast, rather than relying on filters tuned only for yesterday’s known threats.
Account and identity hygiene, MFA, review of connected OAuth applications, and anomaly detection on logins, catches unauthorized access before it turns into an outbound campaign. It deserves its own owner on a security team.
Security awareness training and phishing simulations should mirror incidents like this one. Asaf Cidon, professor of electrical engineering and computer science at Columbia University, has tracked how far AI has pushed the writing quality of phishing attempts: “Their emails were no longer filled with typos and awkward phrases. Instead, they often contained polished, professional-sounding English.” A phishing email sent from a genuinely compromised, trusted account clears that bar without even trying, which is exactly why teams need practice recognizing impersonation from a familiar sender, not just generic “don't click suspicious links” training.
Better detection and sharper training work as two halves of the same defense, sitting alongside the identity and access controls that catch what message-level detection was never built to see.
Practical Steps for Any Organization
A few habits apply regardless of company size or industry, and none of them require waiting for a vendor relationship to start.Grant Ho, the University of Chicago researcher behind the lateral phishing study cited above, led a separate eight-month study of more than 19,500 employees. Generic, annually deployed training barely moved the needle on phishing failure rates. Interactive training built around realistic scenarios cut failure rates by 19 percent among the employees who engaged with it. That gap is exactly why the last habit below calls for simulations built from genuine impersonation patterns rather than generic templates.
- Monitor executive and communications-team accounts for unusual sending patterns, not just suspicious content. Volume and timing are signals on their own.
- Review login and OAuth activity on high-value accounts on a schedule, not only after something looks wrong.
- Keep a calm, pre-written communication ready for the moment impersonation emails may be circulating, instead of drafting one under pressure.
- Build phishing simulations around genuine impersonation scenarios rather than generic templates. Teams recognize what they have practiced against.
Readiness, Not Fear
Every organization with a recognizable name and a large inbox footprint is one compromised account away from a version of this story. That calls for readiness, built now and together, well before the moment arrives.
Nikkei handled a hard week with transparency and speed. The next organization facing this moment deserves the same chance, and a partner that helps build the habits and the detection to get there first.
Learn more about how Adaptive Security’s agentic email security approach helps teams catch impersonation and account-behavior anomalies at adaptivesecurity.com/email-security.