# A Real Email Address Still Needs a Second Check

> Attackers used a genuine Nikkei employee account to send about 9,000 malicious emails. Here is a calm rule for checking an unexpected request when the sender address looks right.

- **Author:** Kubilay Tunca
- **Published:** 2026-10-06
- **Category:** For Mortals
- **Tags:** Phishing, Email Security, Online Safety
- **Canonical URL:** https://cyber-security-in-plain-english.com/post/mortals/news/real-email-address-still-needs-second-check

---

An email from a real colleague, supplier, newspaper or family member feels safer than one from a misspelled address. Usually, that instinct saves time. You recognise the name, see the thread you were already using, and carry on with your day. The awkward part is that a criminal who gets into the mailbox can borrow all of that familiarity.

Nikkei gave us a clear example on 4 October 2026. The Japanese publisher said someone had gained unauthorised access to a Microsoft 365 account used by an employee. On 30 September, messages from the compromised account sent about 9,000 recipients towards a malicious site. Nikkei said the recipients included people inside the company and outside contacts who had previously exchanged messages with employees. Names, email addresses and the contents of some emails may also have been exposed, according to the company's [own notice](https://www.nikkei.co.jp/nikkeiinfo/news/information/1554.html).

The useful lesson is smaller than the headline. A familiar sender address can tell you which mailbox delivered a message, but it cannot always tell you who was sitting behind that mailbox at that moment. When an unexpected email asks you to sign in, pay, download, share a code or change the usual process, check the request through a route you already trust. One short phone call can do more than ten minutes spent studying a logo.

This is a calm rule, not a reason to distrust every message. Most email is ordinary, and you still need to get through your inbox. The trick is to spend your suspicion only where it buys something: on the few messages that ask you to cross a meaningful line.

## What happened at Nikkei

The event began with an ordinary business tool. Nikkei employees use Microsoft 365 for work, including email. The company said a third party appears to have logged in without permission, then used the affected account to send roughly 9,000 messages on 30 September 2026. Those messages contained material intended to lead recipients to a malicious website, and Nikkei later contacted recipients individually to ask them to delete the email.

Nikkei changed the affected password and said that it had seen no further unauthorised logins after that change. It also reported the event to Japan's Personal Information Protection Commission and was still investigating the extent of the affected information when it published its 4 October notice. That qualification matters. The company had established enough to warn people, while the final count and full route into the account were still under examination.

Independent reports broadly match that account. [The Record reported](https://therecord.media/nikkei-cyberattack-japan-data) on 5 October that an attacker used one employee account to send roughly 9,000 phishing emails, including messages to journalistic sources. [The Cyber Express reported](https://thecyberexpress.com/nikkei-cyberattack/) on the same day that the messages went to internal and external contacts, and that they came from a genuine Nikkei account. Neither report turns an unfinished investigation into a neat story about exactly how the attacker got in. As of 6 October, Nikkei had not publicly attributed the event to a named group in the notice cited here.

That leaves a useful boundary around what we know. An employee account was accessed without permission, and about 9,000 messages were sent. Some recipients had a real relationship with Nikkei staff. The attacker's identity and original method remain unknown, but neither is needed to learn from the part that reached the inbox.

Picture a freelance translator who has exchanged documents with a newspaper editor for two years. A new message arrives from the address already saved in the translator's contacts. It refers to familiar work, then asks for a fresh sign-in to view a file. The translator sees no strange domain in the From line because the account itself is the borrowed front door. That is the moment this incident helps us recognise.

## A genuine mailbox can carry a false request

People often talk about phishing as if every bad message arrives in a cheap disguise. We are taught to hunt for a swapped letter in the domain, a fuzzy logo, odd grammar or an unfamiliar greeting. Those clues still catch plenty of rubbish. They become much less useful when the attacker sends through an account that the recipient already knows.

An email address answers a narrow question: which account sent this message? If the account owner is in control, that answer is enough for everyday conversation. Once somebody else has control, the address remains genuine while the intention behind the message changes. Think of a stolen house key. The key can open the correct front door, but that fact does not turn the person holding it into the homeowner.

A compromised mailbox can make the lie fit the relationship. The address may already be in your contacts. Previous messages may show how the sender signs their name, which projects are active and which invoices are expected. Even without reading every old conversation, an attacker benefits from the reputation that the real owner spent years building. The recipient supplies the rest from memory.

The Nikkei notice says some email contents may have been exposed along with names and addresses. That is one reason a mailbox incident deserves more care than a simple list of addresses leaking from a newsletter tool. Old messages carry context. Context can help a dishonest request arrive at a believable time and in a believable voice.

This does not make sender information useless. A completely unknown address remains a useful warning. A misspelled domain remains worth noticing. The lesson is that a correct address cannot carry the whole burden when the message asks you to do something unusual or costly.

That boundary gives you a manageable habit. Read ordinary updates from familiar people in the ordinary way. Pause when the message asks for a password, a login code, a payment, a bank-detail change, a download, a confidential file or an exception to your usual process. The request creates the need for a second check.

## Why inspecting the message can become a trap

When a message feels slightly wrong, many of us turn into amateur detectives. We hover over links, compare signatures, inspect spelling, search for the company logo and reread the greeting. Those checks have value, but they can keep us inside the attacker's chosen room. Every clue in the message is material the sender had a chance to shape.

A real compromised account makes that room especially convincing. The display name can be correct. Replies may stay in a thread you recognise. The signature can match an older email. A malicious link may be hidden behind a button with a familiar service name. None of those details independently confirms that the real person made the present request.

Long examination also creates a strange kind of commitment. After five minutes looking for a flaw and finding none, clicking begins to feel like the reasonable reward for careful work. Yet the absence of a typo never proves control of the account. A polished message can be dangerous, and a clumsy one can be harmless.

The better move is to step outside the message. If the email claims to be from your bank, open the bank app you already use. If a supplier sends new payment details, call the number in your records, not a number supplied in the message. If a colleague sends an unexpected document, ask them in your normal chat or call them. The US Federal Trade Commission gives the same practical advice: contact the company using a phone number or website you know is real, rather than contact information inside the suspicious message ([FTC, December 2024](https://consumer.ftc.gov/consumer-alerts/2024/12/phishing-scams-can-be-hard-spot)).

Replying to the same email is a weak second check. If the mailbox is still under somebody else's control, the attacker can answer. Calling a phone number printed in the suspicious message has the same problem. A second channel works because you choose it independently.

You do not need a forensic answer before you pause. “I was not expecting this” is enough reason to verify a consequential request. You are checking the action, not accusing the sender. A genuine colleague will survive a thirty-second call.

## The line worth checking

Treating every email as hostile would make work and family life miserable. It would also fail, because a rule that demands constant attention soon gets ignored. A useful rule needs a clear line between routine conversation and a request that changes something valuable.

Money is the obvious line. New bank details, gift cards, refunds, invoices, payroll changes and urgent transfers all deserve confirmation through a known route. The FBI describes business email compromise as a scheme that often uses legitimate business or personal accounts to cause an unauthorised transfer of funds ([IC3 guidance, accessed 6 October 2026](https://www.ic3.gov/CrimeInfo/BEC)). You do not have to run a finance department for that pattern to matter. Rent deposits, tradespeople, school fees and family requests can all arrive by email.

Account access is another line. A message that asks you to sign in, approve a notification, read back a code or reset a password deserves a pause. Open the service from your own bookmark or app instead of the email button. If there is a real problem, it should usually appear after you reach the service through that independent route.

Files and software form a third line, particularly when the request is unexpected. An invoice, shared document or compressed folder may be part of ordinary work, but “ordinary” depends on the relationship. If your accountant always sends a PDF and suddenly sends an installer, stop. If a friend who never shares cloud documents sends one without explanation, ask first.

Secrecy and process changes are also worth checking. “Do not call because I am in a meeting” removes the simplest verification route. “Use this new account just this once” asks you to abandon a control at the exact moment it matters. Urgency can be genuine, but genuine urgency can still tolerate a call to a number you already possess.

Everything else can stay light. A newsletter, a meeting update or a note that contains no link and asks for no action does not need a family security conference. Save the stronger check for the doors that lead somewhere.

## A second channel only works when it is truly separate

“Verify it” sounds simple until the verification loops back through the same compromised route. The useful version is more precise: contact the person or organisation through a route that the suspicious message did not give you.

Suppose an email from your conveyancer says the bank account for your house deposit has changed. Do not reply and ask whether the change is real. Find the phone number from your signed paperwork, an old address book entry or the firm's website reached through a fresh search that you check carefully. Call and read the account details back. The few minutes are cheap compared with recovering a misdirected transfer.

For a colleague, use a workplace chat you already used before the email arrived, or call the number already stored in your phone. For a family member, start a fresh message in the conversation you know. For a delivery company, open its official app and enter the tracking number yourself. Each choice leaves the message and returns through a path with its own history.

The method has limits. One person may have lost both email and a messaging account, especially if both can be recovered through the same compromised inbox. A phone number may also have changed. High-value requests deserve a stronger version: use a known voice, a previously agreed process, or two people where your organisation requires approval.

Small businesses can make this easier before anything happens. Agree that bank-detail changes are never accepted by email alone. Keep supplier numbers in the accounting system rather than copying them from an invoice. Let staff know that checking an unusual request is good work, not an accusation or a delay. The control becomes normal when everyone expects it.

Families can use a lighter version. Agree that an unexpected request for urgent money gets a call. If voice imitation worries you, choose a family question whose answer is not public and do not store it in email. The goal is not a dramatic secret code for every conversation. You want one clean route around the account that may have been borrowed.

## What to do if you received one of the messages

If you received a suspicious message that appears to come from Nikkei or another real contact, do not panic and do not keep testing the link. The right response depends on what you did after opening the email. Merely receiving a message calls for less work than entering a password or approving a payment.

1. **Stop using the message as your guide.** Close the page it opened. Do not use its reply address, phone number or “report” button unless your mail service provides that button outside the message content. Keep the email if your workplace security team asks for reports; otherwise follow the affected organisation's current instruction. Nikkei asked the people it contacted to delete the 30 September messages.

2. **Reach the real organisation independently.** Open its official site or use a number you already know. Ask whether the request was genuine. If this is a work account, report it through your normal security or help-desk route so the team can search for related messages.

3. **If you only viewed the email, stop at a proportionate response.** Do not reset every password merely because a message reached your inbox. Report or delete it as appropriate, update your browser and device through their normal settings, and move on. Attention is a limited budget.

4. **If you entered a password, go directly to the real service.** Change that password from a clean route and make it unique. Sign out other sessions, review recent activity and check recovery details. Microsoft provides a [recovery path for hacked or compromised accounts](https://support.microsoft.com/en-us/accounts-billing/manage/how-to-recover-a-hacked-or-compromised-microsoft-account) and a separate control to [sign out a Microsoft account everywhere](https://support.microsoft.com/en-us/accounts-billing/manage/how-to-sign-out-of-your-microsoft-account-everywhere). A work account may require your administrator to perform some of these steps.

5. **If you approved a payment or shared financial details, call the bank now.** Use the number on your card or statement. Ask whether the transfer can be stopped or recalled, then keep the case reference and report the fraud through the route used in your country. Speed can matter here, so do this before writing a perfect timeline.

6. **If you installed a file or program, disconnect it from sensitive work and get help.** A workplace device belongs with the security team. On a personal device, use the built-in security scan and a trusted repair route. Changing passwords on a device that is still being controlled can hand the new password over as well.

7. **Warn the real sender through another channel.** They may not know that their account is sending messages, or they may be handling a flood of replies. A short factual note helps: the time received, the subject, what it asked for and whether you clicked.

This sequence avoids two common mistakes. The first is doing too little after entering credentials because the sender address looked genuine. The second is doing far too much after merely receiving an email. Match the repair to the door you actually opened.

## If your own mailbox sent the messages

Discovering that your account sent mail without you is upsetting, and embarrassment can waste valuable time. Skip the self-blame. A mailbox is both a conversation history and a recovery key for other services, so regain control first and explain later.

Start from a device and route you trust. Change the password to one you have not used elsewhere, then revoke active sessions rather than assuming the password change removes every existing session. Review recent sign-ins, recovery addresses, phone numbers and devices. For personal Microsoft accounts, the [Recent activity page](https://support.microsoft.com/en-us/accounts-billing/security/what-is-the-recent-activity-page) shows account activity from the previous 30 days. Work and school accounts have their own administrator and sign-in tools.

Check the quiet settings that can keep access useful after the obvious password is gone. Look for unfamiliar forwarding addresses, inbox rules, delegates, connected applications and automatic replies. A rule that hides replies or forwards copies can let somebody keep watching the conversation even after they can no longer sign in directly. Microsoft’s administrator guidance for a compromised Microsoft 365 mailbox includes reviewing forwarding, inbox rules, registered authentication methods and application consent, not just changing the password ([Microsoft Learn, accessed 6 October 2026](https://learn.microsoft.com/en-us/defender-office-365/responding-to-a-compromised-email-account)).

Turn on two-step verification if it was absent. Prefer a passkey or security key where the service supports one, because those methods bind the sign-in to the real site more strongly than a code you can be tricked into repeating. Google's explanation of [passkeys](https://developers.google.com/identity/passkeys) describes this resistance to phishing and the use of public-key cryptography rather than a shared secret. A code app still improves an account that had only a password, so do not postpone all protection while shopping for perfect hardware.

Then look outward. Which contacts received messages? What did those messages ask them to do? Which conversations contained personal, financial or confidential information? Tell affected people plainly and through a route they will trust. Give the date, subject line and action to avoid. “My email was hacked” is less useful than “Delete the message sent at 10:14 with the subject Updated invoice; do not use its link.”

If the mailbox belongs to an employer, do not attempt a private clean-up and hope nobody notices. The organisation may need logs that disappear with time, and it may need to search other accounts for the same route in. Report promptly, preserve what you can, and let the team decide the wider scope.

## The habit that survives a better-looking scam

The Nikkei incident is memorable because about 9,000 messages travelled through an account that belonged to a real publisher. The number tells us the scale, but the everyday lesson lives in one recipient's decision. A correct name and familiar address can reduce suspicion without proving the present request.

Cosmetic clues will keep changing. Spelling improves. Logos sharpen. Messages borrow real threads. Security advice that depends on spotting an ugly fake gets weaker as the fake becomes better dressed. A separate route does not care how polished the email looks.

Make the rule narrow enough to keep. When an unexpected email asks you to cross a line involving money, account access, a sensitive file, software or a change to your normal process, leave the message and verify through a route you already trust. Do not reply to ask whether the reply is genuine. Do not call the number the message just supplied.

If the request checks out, you have lost half a minute and reassured the sender that your process works. If it does not, that small pause has protected the thing the message was trying to reach. Either result is useful.

You do not need to distrust your inbox. You need one extra lock for the rare message that asks to be trusted with something valuable.

For more calm, practical security guidance, join the newsletter. It is one email per month.

## Sources

- [Nikkei: Notice concerning information leakage and suspicious emails caused by a cyberattack](https://www.nikkei.co.jp/nikkeiinfo/news/information/1554.html), accessed 2026-10-06
- [The Record: Japanese media group Nikkei discloses intrusions targeting employees and users](https://therecord.media/nikkei-cyberattack-japan-data), accessed 2026-10-06
- [The Cyber Express: Nikkei Cyberattack Hijacks Employee Accounts, Sends 9,000 Spoofed Emails](https://thecyberexpress.com/nikkei-cyberattack/), accessed 2026-10-06
- [Federal Trade Commission: Phishing scams can be hard to spot](https://consumer.ftc.gov/consumer-alerts/2024/12/phishing-scams-can-be-hard-spot), accessed 2026-10-06
- [FBI Internet Crime Complaint Center: Business Email Compromise](https://www.ic3.gov/CrimeInfo/BEC), accessed 2026-10-06
- [Microsoft Support: How to recover a hacked or compromised Microsoft account](https://support.microsoft.com/en-us/accounts-billing/manage/how-to-recover-a-hacked-or-compromised-microsoft-account), accessed 2026-10-06
- [Microsoft Support: How to sign out of your Microsoft account everywhere](https://support.microsoft.com/en-us/accounts-billing/manage/how-to-sign-out-of-your-microsoft-account-everywhere), accessed 2026-10-06
- [Microsoft Support: What is the Recent activity page?](https://support.microsoft.com/en-us/accounts-billing/security/what-is-the-recent-activity-page), accessed 2026-10-06
- [Microsoft Learn: Responding to a compromised email account](https://learn.microsoft.com/en-us/defender-office-365/responding-to-a-compromised-email-account), accessed 2026-10-06
- [Google for Developers: Introduction to passkeys](https://developers.google.com/identity/passkeys), accessed 2026-10-06

---

## About the author

Kubilay Tunca — Senior Full Stack Developer and Author. Founded Cyber Security in Plain English to translate complex security concepts into clear, practical advice, and writes the accompanying books on security, privacy, secure development, and AI systems.

## Books by this author

- **The Digital Fortress** — Your Everyday Guide to a Safer Digital Life. A warm, plain-English guide for people with real lives and finite patience. Learn the handful of habits that genuinely protect your money, accounts, and family, and get honest permission to ignore the rest. [Amazon](https://buy.cyber-security-in-plain-english.com/digital-fortress) · [Details](https://cyber-security-in-plain-english.com/books/the-digital-fortress)
- **The Anonymity Playbook** — Digital Survival for Whistleblowers, Journalists, Activists, and Everyone Else. A practitioner’s field manual for journalists protecting sources, whistleblowers, and activists. It explains how the surveillance actually works, what each technique costs you, and exactly where it fails. [Amazon](https://buy.cyber-security-in-plain-english.com/anonymity-playbook) · [Details](https://cyber-security-in-plain-english.com/books/the-anonymity-playbook)
- **Secure Software Development** — Practical patterns for building secure software. A hands-on security guide for developers and IT professionals who ship real software. Build, deploy, and maintain secure systems without slowing down or drowning in theory. [Amazon](https://buy.cyber-security-in-plain-english.com/secure-software-development) · [Details](https://cyber-security-in-plain-english.com/books/secure-software-development)
- **The Secure Harness** — Shipping Production Code with AI Coding Agents. A calm, practical guide to letting agents do useful work inside boundaries you set, enforce, and audit. Ships with 15 copy-pasteable artifacts: hook scripts, permission configs, release gates, and MCP templates. [Amazon](https://buy.cyber-security-in-plain-english.com/secure-harness) · [Details](https://cyber-security-in-plain-english.com/books/the-secure-harness)
- **The AI Native Engineer** — Build, Evaluate, and Ship AI Systems That Work in Production. Sixteen hands-on chapters, one real product. Grow it from a single model call into a retrieved, tool-using, observable, production-grade system, with evaluation treated as a habit from the first feature. [Amazon](https://buy.cyber-security-in-plain-english.com/ai-native-engineer) · [Details](https://cyber-security-in-plain-english.com/books/the-ai-native-engineer)

Full catalogue with contents and intended audience: https://cyber-security-in-plain-english.com/books

_As an Amazon Associate I earn from qualifying purchases. Buying through these links costs you nothing extra and helps pay for the blog._
