P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

About 9,000 spoofed Nikkei emails reached news sources among others; who was exposed is not yet counted

Nikkei's notice of 4 October says about 9,000 spoofed emails left one Microsoft 365 account on 30 September, with news sources among the recipients, and that recipients' names and addresses are believed leaked. It does not yet say how many people, whose identities, or who did it.

By Parminder Kumar Sharma · · 18 min read

A quiet newsroom desk at night: an open laptop showing a contact list made only of blank rounded pills, and a plain closed notebook with one amber ribbon beside it. No people, no writing on the screen or the notebook.

Nikkei has a number of emails, and no number of people

Nikkei's notice of Sunday 4 October 2026 gives one volume and one date. About 9,000 emails went out from one employee's Microsoft 365 account on 30 September, four days before the notice (derived: 30 September to 4 October). The same notice says Nikkei is still investigating the scope of the breach and the number of personal information records affected. Read at 16:42 BST and re-read unchanged at 17:05 BST on 5 October 2026, it contains no count of people and no count of the news sources among the recipients.

The 9,000 is a count of messages, not of people. The Japanese is 約9000件, about 9,000 items, and no notice says how many distinct recipients there were. It also does not establish what the headlines suggest. It does not say whose identities were exposed, that any source was identified as a source, approached or harmed, or who sent the emails. The Record reports that neither Nikkei incident has been attributed to a specific group, and no attribution appears in any primary source read.

The headline matters. The Record's page, read at 16:42 BST on 5 October, is headed "Japanese media group Nikkei discloses intrusions targeting employees and users". A syndicated copy of the same text on Alo Japan, stamped 13:32 UTC, is headed "discloses cyberattack targeting journalistic sources". Neither wording appears in Nikkei's notices. The notices say news sources were among the recipients of the emails. They do not say the attacker chose sources.

What the notices do support is narrower and still serious. News sources were among the recipients, and recipients' names and email addresses are believed leaked. Together that puts the name and address of any source who received an email inside the believed-leaked data. For someone who needs to stay unknown, the fact of corresponding with a reporter can itself be the secret (judgement). But the notices do not say that any recipient was a confidential source, that anyone's role as a source was exposed, or that the attacker picked sources rather than mailing every correspondent the mailbox held.

What the notices state, and what they do not

Four primary documents were read for the incident itself: Nikkei's Japanese notice 1554 (dated 4 October), its shorter English counterpart 1555 (dated 5 October), Japanese notice 1547 on a Google Workspace account (4 October, no English version found) and Nikkei BP's Japanese notice of 4 October. The Japanese originals were read in Japanese, and translations in this piece are its own unless marked as Nikkei's English. The English notice leaves out the Japanese warning that impersonating emails may increase, so The Record's quotation of that warning is a translation of the Japanese.

What Nikkei's notices of 4 and 5 October 2026 state and do not state about the Microsoft 365 incident. Source: Nikkei notices 1554 (Japanese) and 1555 (English), read at 16:42 BST and re-read unchanged at 17:05 BST on 5 October 2026.

  1. Question
    What was accessed
    Stated
    One employee's Microsoft 365 account. A third party is believed to have logged in (the Japanese says believed).
    Not stated
    Which employee or role, whether a reporter. How the login was obtained. Whether multi-factor authentication was on.
  2. Question
    When
    Stated
    Emails sent on 30 September 2026. Password then changed, no unauthorised login seen since.
    Not stated
    When the first login happened. When and how Nikkei found out.
  3. Question
    How many
    Stated
    About 9,000 emails. Records and people still being investigated.
    Not stated
    Distinct recipients. How many were news sources. How many clicked.
  4. Question
    What data
    Stated
    Recipients' names and email addresses, and the content of some emails, believed leaked.
    Not stated
    Which emails. Whether any revealed that a person was a source. Whether attachments or the contact list were reachable.
  5. Question
    Sources
    Stated
    News sources were among the recipients.
    Not stated
    Whether any was a confidential source. Any harm to, or approach of, a source.
  6. Question
    Who
    Stated
    Nothing.
    Not stated
    Attacker, motive, or any link to the Google Workspace incident or to Nikkei BP.
  7. Question
    Regulator
    Stated
    Reported to Japan's Personal Information Protection Commission.
    Not stated
    Date of the report. Whether voluntary. Any response.
  8. Question
    Told to recipients
    Stated
    Recipients contacted individually and asked to delete the emails. Warning that more impersonating emails may follow.
    Not stated
    What the messages said, by what channel, and whether sources were told differently.

Two more notices from the same Sunday

Nikkei published a second notice that day, number 1547. A Google Workspace account used by one employee was accessed from outside from late July, in the Japanese notice's words 下旬, the last ten or so days of the month. A notification from Google revealed it in early August (上旬, the first ten days). Names and email addresses of 1,646 people, employees and business partners, may be involved. The notice says readers and 取材先 are not included, that no secondary harm has been confirmed, and that the Commission was told. It does not say whether the account has any link to the 30 September emails.

A third company in the group published its own notice. Nikkei BP says an employee's mail account was accessed on 30 September, the same day as the emails, and that the employee's credentials were obtained from a phishing email that arrived from a Nikkei Inc. employee's address. It says 26 items of personal information, names and email addresses, may have leaked, that the connection was cut promptly after the access was discovered, that the Commission was told and that those affected are being emailed individually. The notice does not say the email was part of the 30 September mailing. That link is an inference from the date and the sender, not a stated fact.

Two items are reported but not in a notice. The Yomiuri Shimbun wrote on 5 October that cases of recipients clicking the links were confirmed, without naming who said so; Nikkei's notice does not say it. And The Record notes that Nikkei owns the Financial Times. No notice read mentions the FT, and no FT statement was found as of 17:05 BST on 5 October 2026. Nothing read shows that any UK source was reached.

The fourth Nikkei notice in eleven months

The Japanese notices index shows four incident notices between 4 November 2025 and 4 October 2026, an interval of 334 days (derived). Read in order, the first three each tell readers that source data was outside the incident: not confirmed for Slack, not included for Nikkei America and for Google Workspace. The fourth is the first to say news sources were reached, and the first without a count of people. That comparison is derived from the four texts, not stated by Nikkei.

Nikkei Inc.'s four account-compromise notices since November 2025. Source: Nikkei notices 1393 and 1394, 1489 and 1490, 1547, 1554 and 1555, read in Japanese and English.

  1. Notice
    4 Nov 2025
    System and count
    Slack. Credentials leaked after a virus on an employee's personal computer. Names, addresses and chat histories of 17,368 people.
    What it says about sources
    "No leakage of information related to sources or reporting activities has been confirmed."
  2. Notice
    7 May 2026
    System and count
    Microsoft 365 at Nikkei America. Impersonation mails to business partners in early March. Up to 291 people.
    What it says about sources
    Data "does not include" readers or journalistic sources.
  3. Notice
    4 Oct 2026
    System and count
    Google Workspace. Access from late July, found early August after a Google notification. 1,646 people.
    What it says about sources
    Readers and news sources not included. No secondary harm confirmed.
  4. Notice
    4 Oct 2026
    System and count
    Microsoft 365 at Nikkei Inc. About 9,000 emails on 30 September. Count of people not yet stated.
    What it says about sources
    News sources were among the recipients.
Timeline from 1 September 2025 to 5 October 2026, one row per Nikkei notice. Slack: found September 2025, notice 4 November 2025, 35 to 64 days later. Nikkei America Microsoft 365: mails early March, notice 7 May 2026, 58 to 67 days. Google Workspace: found early August, notice 4 October, 55 to 64 days. Microsoft 365 at Nikkei Inc: mails 30 September, notice 4 October, 4 days; count of people not yet stated.
Drawn from the dates in Nikkei's own notices. Gaps are computed here; ten-day periods such as early August give ranges. The rows date different events.

The arithmetic: Slack was identified in September 2025 and noticed on 4 November, 35 to 64 days later. Nikkei America's emails went out in early March and the notice came on 7 May, 58 to 67 days later. The Google Workspace compromise was found in early August and noticed on 4 October, 55 to 64 days later. The 30 September emails were noticed after 4 days. The rows do not date the same event, and the fourth notice does not say when the account was first accessed or found, so the gaps are not a like-for-like delay and imply no fault. The notices do not say whether any law required them to be public.

All four incidents, as the notices describe them, are an employee's sign-in at a cloud service: chat, mail, a workspace and mail again. None mentions a publishing system, a tip line or a source database, and that silence is not evidence about those systems. One more detail: in March Nikkei announced it would stop accepting emails with password-protected attachments from 18 June 2026, because such files are extremely hard to scan for malware on receipt. The 30 September emails carried links, which that rule does not address. That is a comment on what the control covers, not a finding about how this account was taken.

What Japanese law and its regulator have said

Japan's Act on the Protection of Personal Information treats the press differently from other businesses. Article 57(1)(i), in the e-Gov text in force from 1 October 2026, says that where a newspaper publisher, broadcaster, news agency or other press organisation handles personal information for the purpose of reporting (報道の用に供する目的), the provisions of Chapter IV do not apply. That is this piece's translation. Chapter IV runs from Article 16 to Article 59. It contains Article 23, the duty to take necessary and appropriate security measures, and Article 26, the duty to report a leak to the Personal Information Protection Commission and to tell the people concerned. Article 57(3) leaves a softer duty: such organisations must endeavour (努めなければならない) to take security measures and to publish what they are.

Nikkei says as much itself. Its November 2025 notice says personal information used for reporting and writing is not subject to the Act's duty to report a leak, and that Nikkei reported to the Commission voluntarily, citing the incident's significance and transparency. The 4 October notices say Nikkei reported to the Commission. They do not say whether those reports were voluntary, which data each covered, or when they were filed.

The Commission's own page on leak reporting lists, among the cases where a report is mandatory, a leak that may have been caused by a wrongful act such as unauthorised access. It asks for a prompt report on discovery and, where a wrongful purpose is possible, a report within 60 days of discovery. From 1 October 2026 the page also offers a common report form for other cyber-attack cases, which it says was agreed between ministries and is explained on the National Cybersecurity Office's site. Whether Nikkei used it is not stated.

No public statement about Nikkei from the Commission, the National Cybersecurity Office or the police was found. As of 17:05 BST on 5 October 2026 the Commission's press-release page, as served, listed nothing on Nikkei, with its newest item dated 31 August 2026, and the Office's home page carried no item on it. The Japanese reports read (Kyodo's wire, Yomiuri, NHK's summary and Nikkei's own paper) quote Nikkei alone. "Reported to the regulator" therefore means only that Nikkei says it filed.

The UK position: what the law protects, and what it leaves to you

UK law protects the source in two ways that the Nikkei story does not touch. Section 10 of the Contempt of Court Act 1981 says no court may require a person to disclose "the source of information contained in a publication for which he is responsible", unless disclosure is established to be necessary in the interests of justice or national security or for the prevention of disorder or crime. The Investigatory Powers Act 2016 adds safeguards against state surveillance. An intercepting authority applying for a Part 2 warrant whose purpose includes identifying or confirming a source of journalistic information must say so in the application (section 29). A communications data authorisation made to identify a source takes effect only once a Judicial Commissioner approves it, outside cases of imminent threat to life (section 77). Section 263(1) defines such a source as an individual who provides material intending, or knowing it is likely, that it will be used for journalism.

Each of these constrains a court or a public authority. None mentions an attacker, a mailbox or a notebook, and none says what a newsroom must do to keep its contact records safe. The text was read as served on legislation.gov.uk on 5 October 2026. The Editors' Code of Practice has a clause headed Confidential sources, which could not be read in full because IPSO's site refused automated access.

The duty to keep contact records safe sits in data protection law. Schedule 2, Part 5, paragraph 26 of the Data Protection Act 2018 lets a controller processing for journalism disapply a list of UK GDPR provisions where it reasonably believes publication is in the public interest and that applying them would be incompatible with journalism. The list in paragraph 26(9) includes Article 5(1)(a) to (e), most data subject rights, and Article 34(1) and (4), telling people about a breach. It does not include Article 5(1)(f), the security principle, Article 32, security of processing, or Article 33, notifying the regulator. The ICO's journalism code of practice, in the July 2023 edition read, says so in section 3: "You cannot apply the journalism exemption to the requirement to keep personal information secure." Its paragraph 3.9 names the case: a breach that "could identify a journalist's confidential source", where the code expects strong security "including strict measures controlling access".

How the press exemption treats security and breach duties, Japan against the UK. Sources: e-Gov text of the Act, in force from 1 October 2026; legislation.gov.uk and the ICO journalism code, July 2023 edition, read 5 October 2026.

  1. Question
    Security of data held for journalism
    Japan, Article 57
    Chapter IV does not apply, including Article 23. Article 57(3) asks the press to endeavour.
    UK, Schedule 2 paragraph 26
    Article 5(1)(f) and Article 32 are not on the exemption list. The ICO code says the exemption cannot be applied to security.
  2. Question
    Telling the regulator
    Japan, Article 57
    Article 26 sits in Chapter IV, so it does not apply to data held for reporting. Nikkei called its report on such data voluntary in November 2025.
    UK, Schedule 2 paragraph 26
    Article 33 is not on the list: notify without undue delay, where feasible within 72 hours, unless a risk is unlikely.
  3. Question
    Telling the people affected
    Japan, Article 57
    Article 26(2) sits in Chapter IV, so it does not apply to data held for reporting.
    UK, Schedule 2 paragraph 26
    Article 34(1) and (4) are on the list: the exemption can remove the duty where the controller reasonably believes applying it would be incompatible with journalism.

The same code accepts that contact details are vital to journalism and may justify keeping them "for long periods of time or indefinitely", subject to review (paragraph 10.6). That is a lawful position, and it is also what makes a contact book a rich target. One naming note: the regulator is now the Information Commission, which replaced the Information Commissioner on 30 September 2026, and the body still goes by ICO, now the Information Commission's Office.

The NCSC's guidance for high-risk individuals, published 7 December 2023 and last reviewed 29 May 2024, names journalism among the roles covered. It is written for the person: strong passwords, two-step verification, updates, and keeping to corporately managed accounts and devices for work "as they will be centrally managed and secured". It tells someone who has clicked to report to IT support, and says security teams should not blame them. No separate NCSC page for media organisations was found. Its guidance on phishing, last reviewed 13 February 2024, is for organisations: anti-spoofing controls, authentication that resists phishing, security logging and a rehearsed response.

A promise, a law and an access list

"Source protection" is one phrase for three different things. A promise: Nikkei's published reporting charter says 取材源の秘匿を厳守します, we strictly keep sources confidential, and calls that journalism's lifeline. A law: in the UK, section 10 and the Investigatory Powers Act safeguards, which bind courts and public authorities. And a control: who can sign in to the systems that hold the name. The first two govern what people and the state may do. Neither stops a login.

A source is protected only as far as the weakest system that stores the name. Nikkei's four notices describe four employee accounts at cloud services. In the mailbox case the notice says the emails went to people who had previously communicated with several employees. A mailbox is a contact list, whether or not anyone ever built a source database. Whether the attacker chose sources or mailed everyone the mailbox held is not stated; the second is a common use of a hijacked mailbox (inference, not in the notice).

The NCSC's first layer against phishing is to make spoofing harder: DMARC, SPF and DKIM. Nikkei calls its emails spoofed (なりすまし), but its notice also says a third party logged in to a real account. Mail sent from a real, logged-in mailbox forges nothing, so those checks are unlikely to have stopped it (inference: the notice does not describe how the emails were sent). The layers that would matter are the later ones: sign-in that resists phishing, limits on what one account can reach, logs that catch a mailbox sending thousands of messages, and a rehearsed response. Multi-factor authentication is not enough on its own where the phish steals the session; see the earlier briefing on EvilTokens device-code phishing.

Nikkei BP's notice shows how fast the damage can move. Its employee's credentials were obtained from a phishing email that arrived from a Nikkei employee's address, and its unauthorised access is dated 30 September, the same day as the emails. A message from a trusted address is a credential-harvesting tool at every organisation that trusts it, which is why telling partners matters as much as telling sources.

What to do, in the order worth doing

The order below is this piece's judgement, not law. Each item names the source that supports it where there is one. It applies to newsrooms and communications teams, and equally to any organisation that holds whistleblower or informant records, such as HR whistleblowing hotlines, regulators and charities.

Take this with you

Checklist for holders of source and whistleblower records (judgement, in order)

  • Map every place a name lives: mailboxes, phones, notebooks, chat, the content system, shared drives, backups and any hotline supplier. A list you have not drawn cannot be protected.
  • Store less about each source. Keep names out of story files and chat, delete what a story no longer needs, and put a review date on contact details. The ICO code expects periodic review and accepts long retention only where justified (paragraphs 9.9 and 10.6).
  • Move source records out of the general mailbox and chat into a separate, encrypted store with its own sign-in. UK GDPR Article 32 names encryption and pseudonymisation among appropriate measures.
  • Limit who can open source records and log every read. Alert on bulk reads, new forwarding rules, and a mailbox sending far more than usual. The NCSC says to use security logging to catch incidents users are not aware of.
  • Treat the mailbox and contact list as crown jewels. Use sign-in that resists phishing, such as passkeys or hardware keys, for everyone who holds sources, with no shared accounts and separate administrator accounts.
  • Give sources a way in that does not touch a staff mailbox: a published secure submission channel, and a rule that first contact moves off email.
  • Write and rehearse the message to sources. Decide who sends it, on which channel other than the affected mailbox, what it says and how a source can check it is genuine. Nikkei contacted recipients individually and asked them to delete the emails. Warn partner organisations in the same hour.
  • Take legal advice now on disclosure duties. UK GDPR Article 33 asks for notice to the regulator without undue delay and where feasible within 72 hours, and the journalism exemption does not remove it. Whether to tell the people affected is a separate decision on which the exemption can apply. A hotline, charity or regulator cannot rely on the journalism carve-out in paragraph 26, so take advice on which security and breach duties apply to it, and check supplier contracts as well.

The question to ask before the mailbox is read

Nikkei's notice says it is still working out the count, four days after the emails went out. The law that protects sources from courts and from state surveillance has no bearing on that count. What decides it is the access list, the logs and the rehearsal that existed before 30 September.

If the mailbox of the person who talks to your most sensitive source were read by a stranger tonight, how many names would you be counting tomorrow, and could you tell each of them, in the same hour, in a way they could check was really you?

Key facts

Sources

  1. PrimaryNotice of 4 October 2026 on the Microsoft 365 account and the spoofed emails, read in Japanese: about 9,000 emails, 30 September, news sources among recipients, report to the Personal Information Protection Commission, password changedNikkei Inc.accessed 2026-10-05
  2. PrimaryEnglish counterpart of the same notice, dated 5 October 2026: 'contacts inside and outside the company, including news sources'; shorter than the Japanese, without the warning about further impersonating emailsNikkei Inc.accessed 2026-10-05
  3. PrimaryNotice of 4 October 2026 on the Google Workspace account, read in Japanese: access from late July, found early August by a Google notification, 1,646 people, readers and news sources not includedNikkei Inc.accessed 2026-10-05
  4. PrimaryNotice of 4 October 2026, read in Japanese: access to an employee's mail account on 30 September, credentials obtained from a phishing email that arrived from a Nikkei Inc. employee's address, 26 items of personal informationNikkei Business Publications (Nikkei BP)accessed 2026-10-05
  5. PrimaryEnglish notice of 4 November 2025 on the Slack incident: 17,368 people, credentials leaked after a virus on a personal computer, voluntary report to the Commission, no leak of source information confirmedNikkei Inc.accessed 2026-10-05
  6. PrimaryJapanese original of the Slack notice: damage identified in September 2025; the sentence that reporting-purpose personal information is outside the Act's duty to reportNikkei Inc.accessed 2026-10-05
  7. PrimaryEnglish notice of 7 May 2026 on Microsoft 365 at Nikkei America: impersonation mails in early March, up to 291 people, data does not include readers or journalistic sourcesNikkei Inc.accessed 2026-10-05
  8. PrimaryJapanese original of the Nikkei America notice, used to check the wording 'readers or reporting' behind the English 'readers or journalistic sources'Nikkei Inc.accessed 2026-10-05
  9. PrimaryEnglish notice of 27 March 2026: Nikkei stops accepting emails with password-protected attachments from 18 June 2026 because they cannot be scanned (Japanese version 1463 also read)Nikkei Inc.accessed 2026-10-05
  10. PrimaryNikkei's reporting charter, read in Japanese: the commitment to keep the confidentiality of sources (取材源の秘匿を厳守します); no English version foundNikkei Inc.accessed 2026-10-05
  11. PrimaryAct on the Protection of Personal Information, revision in force from 1 October 2026, read in Japanese through the e-Gov API: Articles 23, 26 and 57 and the Chapter IV structuree-Gov, Government of Japanaccessed 2026-10-05
  12. PrimaryCommission page on leak reporting, read in Japanese: mandatory report cases, prompt report and the 60 day period, the common cyber-attack report form from 1 October 2026Personal Information Protection Commission (Japan)accessed 2026-10-05
  13. PrimaryPress-release page as served on 5 October 2026: no item on Nikkei, newest entry dated 31 August 2026Personal Information Protection Commission (Japan)accessed 2026-10-05
  14. PrimaryHome page as served on 5 October 2026: no item on NikkeiNational Cybersecurity Office (Japan)accessed 2026-10-05
  15. PrimaryContempt of Court Act 1981, section 10 (sources of information), read as served on 5 October 2026legislation.gov.ukaccessed 2026-10-05
  16. PrimaryInvestigatory Powers Act 2016, section 29 (sources of journalistic information, interception warrants); sections 28, 77, 114, 154, 195, 263 and 264 also readlegislation.gov.ukaccessed 2026-10-05
  17. PrimaryInvestigatory Powers Act 2016, section 77 (Judicial Commissioner approval of communications data authorisations to identify or confirm a journalistic source)legislation.gov.ukaccessed 2026-10-05
  18. PrimaryInvestigatory Powers Act 2016, section 263 (interpretation): the definition of a source of journalistic informationlegislation.gov.ukaccessed 2026-10-05
  19. PrimaryData Protection Act 2018, Schedule 2, Part 5, paragraph 26 (journalistic, academic, artistic and literary purposes) and the list of exempted UK GDPR provisions in paragraph 26(9)legislation.gov.ukaccessed 2026-10-05
  20. PrimaryUK GDPR Article 33 (notification of a personal data breach to the regulator); Articles 5, 32 and 34 also readlegislation.gov.ukaccessed 2026-10-05
  21. PrimaryData protection and journalism code of practice, July 2023 edition as served: section 3 (keep personal information secure), paragraphs 3.9 and 10.6Information Commissioner's Officeaccessed 2026-10-05
  22. PrimaryNews item of 30 September 2026: the ICO formally transitioned to the Information CommissionInformation Commission's Officeaccessed 2026-10-05
  23. PrimaryGuidance for high-risk individuals, published 7 December 2023, reviewed 29 May 2024: journalism named among high-risk roles; corporately managed accounts; reporting a click without blameNational Cyber Security Centreaccessed 2026-10-05
  24. PrimaryPhishing attacks: defending your organisation, version 2.0, reviewed 13 February 2024: four layers, DMARC, SPF and DKIM, authentication, security logging, rehearsed responseNational Cyber Security Centreaccessed 2026-10-05
  25. Reported byReport read at 16:42 BST on 5 October 2026 under the headline 'discloses intrusions targeting employees and users': used for the claims to check, not as a source of factThe Record from Recorded Future Newsaccessed 2026-10-05
  26. Reported bySyndicated copy of The Record's text, stamped 13:32 UTC on 5 October 2026 and headed 'discloses cyberattack targeting journalistic sources': evidence of the earlier headlineAlo Japanaccessed 2026-10-05
  27. Reported byReport of 5 October 2026, read in Japanese: the statement, not attributed to a named speaker, that cases of recipients clicking were confirmedYomiuri Shimbun via Infoseekaccessed 2026-10-05
  28. Reported byWire report read in Japanese: repeats Nikkei's notice and quotes no regulator or police sourceToonippo (Kyodo wire)accessed 2026-10-05
  29. Reported byNikkei's own report of its incident, free portion read in Japanese: repeats the noticeNikkei (newspaper)accessed 2026-10-05
  30. Reported byJapanese incident summary of 5 October 2026: cross-check that Nikkei BP's notice says only that the phishing email arrived from a Nikkei employee's addresspiyologaccessed 2026-10-05

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

How often

Every new briefing in one email, at 7am, or at 7am, 12:30pm and 6pm. Nothing is sent when nothing is new. Unsubscribe any time.