Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

Nikkei Says 17,000 Impacted by Data Breach Stemming From Slack Account Hack

The Japanese media giant says compromised Slack credentials were used to steal employee and business partner information.

Wired data leak

Japanese media giant Nikkei on Tuesday reported that hackers had gained access to employee Slack accounts, stealing information pertaining to thousands of individuals.

Nikkei, which is best known for major financial publications such as The Nikkei and Financial Times, said the incident involved malware stealing Slack credentials from an employee’s personal computer. 

The credentials were then used to access employee Slack accounts, which enabled the attacker to steal information pertaining to employees and business partners. 

An investigation showed that names, email addresses and chat histories belonging to over 17,000 of Nikkei’s Slack users were compromised.

“No leakage of information related to sources or reporting activities has been confirmed,” the company clarified.

The hack was discovered in September and passwords have been changed as part of the company’s incident response procedures. 

Advertisement. Scroll to continue reading.

Nikkei noted that while the type of compromised information did not require it to disclose the data breach to authorities, it decided to voluntarily report the incident to Japan’s Personal Information Protection Commission.

Infostealer malware has been known to collect Slack credentials from infected devices. Hudson Rock, which closely monitors infostealer activity, reports that this type of malware has compromised more than 270,000 Slack credentials. The company has identified the infostealer instance that was likely reponsible for the theft of Nikkei Slack credentials.

This is not the only data breach disclosed by Nikkei in recent years. In 2022, the company was targeted in a ransomware attack that impacted customer information.

Related: 10 Million Impacted by Conduent Data Breach

Related: Open VSX Downplays Impact From GlassWorm Campaign

Related: Cybercriminals Trade 183 Million Stolen Credentials on Telegram, Dark Forums

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

With "Shadow AI" usage becoming prevalent in organizations, learn how to balance the need for rapid experimentation with the rigorous controls required for enterprise-grade deployment.

Register

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

People on the Move

AutoNation has appointed Brian Fricke as Chief Information Security Officer.

Varun Kohli has joined GetReal Security as Chief Marketing Officer.

MongoDB has appointed Doug Bowers as Chief Information Security Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.