Full Report
Over the weekend, Japanese publishing giant Nikkei disclosed that unknown attackers recently breached two employee email accounts and used one to send thousands of phishing emails. [...]
Analysis Summary
# Incident Report: Compromise of Nikkei Microsoft and Google Workspace Accounts
## Executive Summary
Japanese media giant Nikkei disclosed two separate breaches of employee email accounts occurring between July and September 2024. Attackers gained unauthorized access to a Google Workspace account to harvest PII and subsequently breached a Microsoft 365 account to distribute approximately 9,000 phishing emails to internal staff and external interviewees. The company has since rotated credentials and notified affected parties, though the incidents highlight a recurring pattern of targeting against the organization.
## Incident Details
- **Discovery Date:** Early August 2024 (Google); September 30, 2024 (Microsoft 365)
- **Incident Date:** Late July 2024 – September 30, 2024
- **Affected Organization:** Nikkei Inc.
- **Sector:** Media / Publishing
- **Geography:** Japan (Global impact)
## Timeline of Events
### Initial Access
- **Date/Time:** Late July 2024
- **Vector:** Unauthorized login to Google Workspace account (Method not disclosed, likely credential theft).
- **Details:** Attackers accessed an employee's Google Workspace account, gaining access to stored contact information.
### Lateral Movement
- **Details:** While not explicitly detailed as lateral movement, a second breach occurred in September 2024 involving a Microsoft 365 account. It is currently unconfirmed if the two breaches are technically linked.
### Data Exfiltration/Impact
- **PII Exposure:** Names and email addresses of 1,646 individuals (employees and business partners) were exposed in the July breach.
- **Phishing Campaign:** On September 30, 2024, attackers used the compromised M365 account to send 9,000 malicious emails to internal staff and external interviewees.
### Detection & Response
- **August 2024:** Google notified Nikkei of suspicious activity, leading to the discovery of the July breach.
- **September 30, 2024:** Detection of mass phishing emails sent from the internal Microsoft 365 account.
- **Immediate Action:** Nikkei performed password resets for affected accounts and issued individual warnings to phishing recipients.
## Attack Methodology
- **Initial Access:** Credential compromise (specific method like Phishing or Credential Stuffing is suspected but unconfirmed).
- **Persistence:** Unauthorized session access to cloud mail environments.
- **Defense Evasion:** Use of legitimate corporate infrastructure (Nikkei’s own M365 tenant) to send phishing emails, bypassing external spam filters.
- **Collection:** Harvesting of contact lists and PII from email accounts and cloud storage.
- **Exfiltration:** Exfiltration of contact information for 1,646 individuals.
- **Impact:** Phishing (9,000 emails) and data breach of business partner information.
## Impact Assessment
- **Financial:** Undisclosed (likely costs associated with incident response and forensics).
- **Data Breach:** Exposure of names and emails for 1,646 individuals; potential compromise of email communications.
- **Operational:** Disruption to communications; necessity for manual outreach to 9,000 phishing targets.
- **Reputational:** High; this is the latest in a series of breaches including a 2023 Slack breach and a 2022 ransomware attack.
## Indicators of Compromise
- **Behavioral indicators:**
- Unauthorized logins from atypical geographic locations or IP ranges.
- Mass outbound email volume (9,000 emails) from a single user account in a short timeframe.
- Presence of "links to malicious websites" within internal/external correspondence.
## Response Actions
- **Containment:** Forced password resets for compromised Google and Microsoft accounts.
- **Eradication:** Monitoring for further unauthorized logins (none confirmed post-reset).
- **Recovery:** Contacting all 9,000 recipients individually to request deletion of the malicious emails.
- **Communication:** Public disclosure and advisory for partners to watch for Nikkei-impersonation attacks.
## Lessons Learned
- **Detection Delay:** The July breach was discovered in August only after a third-party (Google) notification, indicating a need for better internal telemetry.
- **Recurring Target:** Nikkei is a frequent target for BEC and phishing, suggesting that threat actors have identified the organization's staff as high-value targets.
- **Cloud Security:** Dependence on single-factor or weak MFA may have contributed to the ease of account takeover.
## Recommendations
- **MFA Hardening:** Implementation of FIDO2-compliant hardware security keys to prevent MFA bypass (AiTM) phishing attacks.
- **Mail Security:** Implement stricter outbound rate limits and "impossible travel" alerts for Microsoft 365 and Google Workspace.
- **Security Awareness:** Enhanced training for journalists and staff on identifying sophisticated phishing attempts, as they are frequently in contact with external parties.
- **Logging & Monitoring:** Improve SIEM/SOC visibility into cloud logs to identify unauthorized access without relying on vendor notifications.