Nikkei, a major Japanese media conglomerate and owner of the Financial Times, confirmed that its internal network was breached after attackers compromised an employee's Slack account. The breach, discovered in September, resulted from malware infecting an employee's computer, which allowed hackers to steal authentication credentials and gain unauthorized access to the company's Slack messaging platform. As a result, sensitive data belonging to business partners and chat histories of 17,368 Slack users—including employees and partners—were exposed. Nikkei responded by implementing multiple countermeasures, such as mandatory password resets, and reported the incident to Japan’s data protection authorities, despite the leaked data not falling under the country’s personal information protection laws.
The company stated that there is no evidence suggesting any compromise of journalistic sources or reporting-related information. Nikkei emphasized its commitment to transparency and pledged to strengthen personal information management to prevent future incidents. The breach highlights the growing risk of collaboration tools like Slack being targeted for credential theft and lateral movement within corporate networks. This incident follows a previous ransomware attack on Nikkei’s Singapore headquarters in 2022 and comes amid a broader trend of cyberattacks targeting media organizations worldwide.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
Although Nikkei assessed the incident did not trigger mandatory reporting under Japan's Personal Information Protection Law, it said it voluntarily notified Japan's Personal Information Protection Commission. This notification was disclosed as part of the company's public response to the incident.
In early November 2025, Nikkei publicly reported that personal information for 17,368 Slack-registered employees and business partners may have been exposed in the breach. The company said confidential source information and journalistic-purpose personal data were not affected.
Nikkei discovered in September 2025 that its Slack environment had been compromised and required password changes for affected accounts. The intrusion potentially exposed names, email addresses, and Slack chat histories.
Nikkei said attackers obtained authentication credentials after malware infected an employee's computer, enabling unauthorized access to the company's Slack environment. The exact date of the initial compromise was not disclosed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
8 references tracked. Mallory keeps watching after this page renders.
go.theregister.com
Open sourcecsoonline.com
Open sourcecsoonline.com
Open sourcedarkreading.com
Open sourcehackread.com
Open sourcescworld.com
Open sourcetherecord.media
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.