Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

Nikkei Says 17,000 Impacted by Data Breach Stemming From Slack Account Hack

The Japanese media giant says compromised Slack credentials were used to steal employee and business partner information.

Wired data leak

Japanese media giant Nikkei on Tuesday reported that hackers had gained access to employee Slack accounts, stealing information pertaining to thousands of individuals.

Nikkei, which is best known for major financial publications such as The Nikkei and Financial Times, said the incident involved malware stealing Slack credentials from an employee’s personal computer. 

The credentials were then used to access employee Slack accounts, which enabled the attacker to steal information pertaining to employees and business partners. 

An investigation showed that names, email addresses and chat histories belonging to over 17,000 of Nikkei’s Slack users were compromised.

“No leakage of information related to sources or reporting activities has been confirmed,” the company clarified.

The hack was discovered in September and passwords have been changed as part of the company’s incident response procedures. 

Advertisement. Scroll to continue reading.

Nikkei noted that while the type of compromised information did not require it to disclose the data breach to authorities, it decided to voluntarily report the incident to Japan’s Personal Information Protection Commission.

Infostealer malware has been known to collect Slack credentials from infected devices. Hudson Rock, which closely monitors infostealer activity, reports that this type of malware has compromised more than 270,000 Slack credentials. The company has identified the infostealer instance that was likely reponsible for the theft of Nikkei Slack credentials.

This is not the only data breach disclosed by Nikkei in recent years. In 2022, the company was targeted in a ransomware attack that impacted customer information.

Related: 10 Million Impacted by Conduent Data Breach

Related: Open VSX Downplays Impact From GlassWorm Campaign

Related: Cybercriminals Trade 183 Million Stolen Credentials on Telegram, Dark Forums

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Stephen Garcia has been named Chief Information Security Officer at BreachRx.

Kasper Lindgaard has been appointed Vice President of Security Strategy at CoreView.

Chaim Mazal has been named Chief Information Security Officer at GitLab.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.