Nikkei, the Japanese media group that owns the Financial Times, disclosed two cyber incidents involving employee accounts. In the more recent case, an attacker compromised a Microsoft 365 account and used it to send roughly 9,000 phishing emails on September 30. The messages went to people inside and outside the company, including journalistic sources, and contained links to malicious websites. Nikkei said it changed the password for the compromised account, detected no further unauthorized access, and asked recipients to delete the messages.

Earlier the same day, Nikkei reported that a Google Workspace account had been accessed without authorization since late July. That intrusion potentially exposed names and email addresses of 1,646 employees and business partners. Nikkei said it discovered the issue after an alert from Google in early August, changed the password, and found no evidence that the exposed information had been misused. The company said that incident did not involve data related to readers or journalistic sources.

Nikkei has not said whether the two incidents are connected, and neither has been attributed to a specific hacking group. The disclosures add to a recent string of cyber incidents at major Japanese companies, including Daiwa Securities and Yamato Transport. Nikkei itself has faced previous breaches, including a November 2025 intrusion involving Slack and a 2022 ransomware attack.