Security · October 8, 2026
Microsoft 365 accounts compromised in cyber attack
A cyber attack has reportedly targeted the accounts of employees using Microsoft 365 at a major Japanese company. This incident has led to the sending of a large number of spoofed emails.
The company disclosed that unauthorized access was gained to employee accounts. It is believed that a third party logged in unlawfully, potentially compromising email addresses, names, and some content of the emails.
On September 30, 2026, around 9,000 spoofed emails were sent to various recipients, including internal staff and sources the company interacted with. The emails contained links directing recipients to malicious websites.
In response to the incident, the company changed the passwords for the affected accounts. Since then, no further unauthorized logins have been reported.
The company has reached out individually to recipients of the spoofed emails, requesting them to delete the messages. They have also warned that there may be an increase in spoofed emails impersonating the company and its affiliates in the future.