Nikkei Reports Google Workspace Unauthorized Access and About 9,000 Phishing Emails via Microsoft 365
1. Basic Information Article Title: Information Leakage and Suspicious Email Sending Due to Cyber Attack Publisher: Nikkei Inc. Publication Date: October 4, 2026 Report Update Reason: Primary source verification:
1. Basic Information
- Article Title: Information Leakage and Suspicious Email Sending Due to Cyber Attack
- Publisher: Nikkei Inc.
- Publication Date: October 4, 2026
- Report Update Reason: Primary source verification: Changed the main source to Nikkei's October 4 announcement and corrected the confidence and scope of Microsoft 365 unauthorized logins and data leaks, the denominator of approximately 9,000 emails, the timeline for Google Workspace, and the notification and reporting status.
- Original Source: Nikkei Inc.: Microsoft 365 Incident
- Related Sources: Nikkei Inc.: Google Workspace Incident, BleepingComputer
- Related Malware: Unknown
- Related Threat Groups: Unknown
- Related CVEs: None
- Related Products and Services: Google Workspace, Microsoft 365
- Severity: High
2. Executive Summary
In separate October 4 announcements, Nikkei Inc. disclosed unauthorized logins to Google Workspace accounts used by its employees and phishing emails sent using employees' Microsoft 365 accounts. In the Google Workspace incident, email addresses, names, and other information relating to 1,646 people, including employees and business partners, may have been exposed. In the Microsoft 365 incident, third parties are believed to have logged in without authorization, and approximately 9,000 phishing emails were sent on September 30. Recipient email addresses and names, along with the contents of some emails, are also believed to have been exposed. The scope of the compromise and the number of personal information records potentially exposed remain under investigation. The relationship between the incidents and the initial access methods are unknown.
3. Attack Flow
The two incidents were disclosed in separate announcements, and it has not been confirmed that they form a continuous attack chain.
Attack Vector A: Google Workspace Account
- External unauthorized logins to employees' Google Workspace accounts occurred from late July onward.
- The incident was discovered in early August following a notification from Google, and the company immediately changed its passwords. No subsequent unauthorized logins have been confirmed.
- Email addresses, names, and other details of 1,646 individuals, including employees and business partners, may have been exposed. Information regarding readers and sources is not included.
- The company reported the incident to the Personal Information Protection Commission. As of the October 4 announcement, no secondary damage has been confirmed.
Attack Vector B: Microsoft 365 Account
- Employees' Microsoft 365 accounts were subjected to a cyber attack, and third parties are believed to have logged in without authorization. The date and time of the initial unauthorized login are not specified in the primary announcement.
- On September 30, approximately 9,000 phishing emails containing links to malicious sites were sent to internal recipients as well as sources and others who had communicated with multiple employees.
- In addition to recipient email addresses and names, the contents of some emails are also believed to have been exposed. The scope of the compromise and the number of personal information records leaked are under investigation, and the 9,000 figure represents the number of sent emails.
- The company reported the incident to the Personal Information Protection Commission, and no unauthorized logins have been confirmed since the password changes. Recipients were individually contacted and asked to delete the emails. Recipient clicks and subsequent compromises have not been disclosed.
4. Attacker Location and Execution Environment
- For Google Workspace, external unauthorized logins were confirmed. For Microsoft 365, third parties are believed to have logged in without authorization, but the acquisition methods and connection sources have not been made public.
- The suspicious emails were sent using Microsoft 365 accounts to internal and external recipients. Sending, delivery, and opening should be assessed separately.
- The credential acquisition methods, MFA status, and potential abuse of OAuth apps or session cookies are unknown.
5. Visibility for Victims and Administrators
- Recipients: Because emails containing links to malicious sites arrive from known Nikkei Inc. employee accounts, it is difficult to determine authenticity based solely on the sender display name.
- Administrators: Clues include unknown logins to employee accounts, sudden high-volume sending, approximately 9,000 messages sent to internal and external recipients, and security notifications from Google.
- On the Google Workspace side, it has not been disclosed where within contacts, mail, or files the information for the 1,646 individuals was exposed.
6. Success and Failure Conditions
Success Conditions
- Attackers obtain employee account credentials, sessions, or tokens and satisfy the authentication requirements of Google Workspace or Microsoft 365.
- The compromised account has authorization to view or send emails and access related information.
- While link-based phishing relies on recipients accessing malicious links to serve as an entry point for follow-up attacks, this alone does not indicate successful credential theft or code execution. Additional user input, actions, or exploitation conditions are undisclosed, and recipient clicks have not been confirmed.
Failure Conditions
- Blocking logins from unknown devices or locations using phishing-resistant MFA, conditional access, and risk-based sign-in controls.
- Revoking sessions and tokens, changing passwords, and reviewing OAuth grants, inbox rules, and forwarding rules.
- Monitoring outgoing volume, recipient expansion, and malicious URLs per account, and promptly halting high-volume transmissions.
7. What Happens Upon Success
- In the Google Workspace incident, email addresses, names, and other details of 1,646 individuals, including employees and business partners, may have been exposed.
- In the Microsoft 365 incident, approximately 9,000 phishing emails were sent. This figure represents the number of sent emails and does not indicate the number of individuals affected or personal records leaked.
- On the Microsoft 365 side, recipient email addresses and names, as well as some email contents, are believed to have been exposed. The scope of compromise and the number of leaked personal records are under investigation.
- Secondary damage from the Google Workspace incident remained unconfirmed as of the October 4 announcement. For the Microsoft 365 incident, recipient clicks, credential theft, malware execution, and account compromises have not been disclosed.
8. Observable Logs
- Email: Check for surges in sending volume from compromised accounts, unusual recipients, malicious URLs, and delivery or click telemetry.
- Proxy / SWG / DNS: Check for access to URLs within suspicious emails, redirect chains, newly registered domains, and subsequent downloads.
- Endpoint / EDR: Check for browsers, scripts, downloads, and child processes following link clicks. Account compromise alone may not generate endpoint events.
- Identity / IdP: Check Google and Microsoft sign-in logs, unknown IPs, devices, and regions, impossible travel, MFA events, and session or token issuance.
- SaaS / Cloud: Check mailbox access, mail searches, exports, OAuth grants, inbox and forwarding rules, sent items, and role changes.
- Network: Check source IPs for logins to cloud email services and communications from recipient terminals to malicious sites.
9. Attack Success Assessment
Confirmed in Public Information
- Malware Execution or Successful Authentication Confirmed: External unauthorized logins to Google Workspace accounts have been confirmed. For Microsoft 365, the company stated that third parties are believed to have logged in without authorization, which is not treated as a confirmed successful authentication of the same certainty. The credential acquisition methods, presence of MFA, and the necessity and success of bypasses are unknown.
- For Google Workspace, there is a possibility of leaks regarding email addresses and names of 1,646 individuals. For Microsoft 365, the company stated that recipient email addresses and names and some email contents are believed to have been exposed. The actual acquisition scope and number of leaked personal records remain undetermined.
- Attack Attempt Observed (Success Unconfirmed): The transmission of approximately 9,000 phishing emails using Microsoft 365 accounts was announced. Recipient clicks and successful compromises remain unconfirmed. The 9,000 figure must not be misinterpreted as the number of individuals whose data was leaked or unique recipients.
Criteria for Internal Determination
- Information Theft or Session Compromise Confirmed: Determine this only when unauthorized access to or acquisition of target information or unauthorized session use is substantiated by audit logs. Mere suspicion of a leak does not confirm success at this stage.
- Correlate successful sign-ins, sessions, tokens, mailbox access, and sending events to evaluate account access, data access, high-volume sending, and recipient compromise on a step-by-step basis.
10. Investigation Playbook
- Investigation Starting Point: Google and Microsoft risk alerts, unknown logins, high-volume sending, and malicious URLs originating from legitimate accounts.
- Initial Verification: Check target accounts, login times, IPs, devices, MFA, sessions, sending counts, recipients, and URLs.
- Endpoint and Server Investigation: Check account owner terminals for browsers, credential theft, infostealers, session cookies, and password manager events.
- Authentication and Cloud Investigation: Check sign-ins, mailbox audits, OAuth grants, forwarding and inbox rules, delegations, and token issuance.
- Tracking Follow-up Actions: Track mail and file views, contact extractions, external transmissions, recipient clicks, and additional account compromises.
- Containment: Revoke sessions and tokens, change passwords, re-register MFA, and remove malicious rules and apps. Remove or contain malicious messages in mailboxes under the organization's control using available remediation tools, and notify external recipients to request deletion.
- Categorization: Separate login attempts, successful authentication, mailbox access, data exposure, high-volume sending, recipient clicks, and follow-up compromises.
11. Defense and Detection Ideas
- Single Events: Prioritize cloud email logins from unknown devices or locations and high-risk sign-ins.
- Time-Series Correlation: Correlate suspicious logins, mailbox searches or exports, recipient expansion, high-volume sending, and recipient clicks.
- Threat Hunting: Search for new OAuth consents, forwarding rules, delegates, changes to MFA methods, and sudden short-term surges in sending volume.
- Log Limitations: Mailbox operations, sessions, and click telemetry may be missing due to retention limits or license tiers. Do not assume all past sessions are revoked merely by changing passwords.
- Priority Countermeasures: Prioritize phishing-resistant MFA, session revocation procedures, mailbox audits, sending rate alerts, and prompt notifications to external recipients.
12. Facts / Inference / Hypothesis
Facts
- External unauthorized logins to Google Workspace accounts occurred starting in late July, which was identified through a Google notification in early August. No unauthorized logins have been confirmed after password changes.
- On the Google Workspace side, email addresses, names, and other details of 1,646 individuals, including employees and business partners, may have been exposed. Information regarding readers and sources is not included, and no secondary damage was confirmed as of the October 4 announcement.
- On the Microsoft 365 side, third parties are believed to have logged in without authorization, and approximately 9,000 phishing emails were sent on September 30 to internal recipients and sources who had communicated with multiple employees.
- On the Microsoft 365 side, recipient email addresses and names, as well as some email contents, are believed to have been exposed. The company is investigating the scope of the compromise and the number of personal information records leaked. The 9,000 figure represents the number of sent emails.
- For Microsoft 365, Nikkei reported no further unauthorized logins after changing passwords. Recipients were contacted individually and asked to delete the emails. Both incidents were reported to Japan's Personal Information Protection Commission.
- The threat actor, the relationship between the two incidents, and the credential acquisition methods have not been disclosed.
Inference
- Because legitimate accounts are used as senders, reliance solely on gateway sender reputation may delay detection. Correlation between identity and sending behavior is crucial.
Hypothesis
No additional hypotheses. Unconfirmed items are listed in "14. Unknowns and Additional Investigation."
13. MITRE ATT&CK Mapping
| ID | Technique | Confidence | Basis |
|---|---|---|---|
| T1078.004 | Valid Accounts: Cloud Accounts | high | Unauthorized logins to legitimate employee accounts in Google Workspace have been confirmed. For Microsoft 365, the company stated that third parties are believed to have logged in without authorization. |
| T1566.002 | Phishing: Spearphishing Link | high | Approximately 9,000 phishing emails containing links to malicious sites were sent using Microsoft 365 accounts. |
14. Unknowns and Additional Investigation
- Methods used to acquire credentials or sessions, presence of MFA, necessity and success of bypasses, and intrusion sources.
- The location where the information for 1,646 individuals resided in Google Workspace and the actual scope of data acquired.
- For the Microsoft 365 incident, the date and time of the first unauthorized login, the scope of the compromise, the number of personal information records potentially exposed, and the extent of any email-content exposure.
- Recipient click counts, credential theft, malware execution, and subsequent account compromises in the Microsoft 365 incident.
- Whether the two incidents involve the same actor or campaign.
15. Impact on SOCs and Organizations
Attackers who compromise a media organization's account can exploit the trust that colleagues and news sources place in its employees, potentially enabling widespread phishing against those contacts. Organizations should investigate sessions, tokens, OAuth grants, mailbox rules, sending history, and recipient clicks alongside password changes, and maintain a process for promptly notifying external recipients.
16. Target-Specific Summaries
- For SOCs: Correlate cloud sign-ins, mailbox operations, high-volume sending, and recipient clicks in a time series, and investigate the two incidents independently.
- For Administrators: Revoke sessions and tokens, re-register MFA, and audit OAuth grants and mailbox rules. Remediate malicious messages in mailboxes under your control, and notify external recipients to request deletion.
- For Users: Even when emails come from actual employee accounts, do not open suspicious links; verify with the sender through a separate channel.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.