Home » Nikkei’s Slack breach leaks sensitive data from more than 17,000 users

Nikkei’s Slack breach leaks sensitive data from more than 17,000 users

by
2 minutes read

Nikkei’s Slack Breach: A Cautionary Tale for Data Security

In a recent cybersecurity incident, Japanese media giant Nikkei fell victim to a breach that compromised the sensitive information of over 17,000 users through their Slack accounts. This breach serves as a stark reminder of the risks associated with allowing non-corporate devices to access confidential corporate data.

According to Nikkei’s statement, the breach originated from an employee’s personal computer being infected with a virus, leading to the exposure of Slack authentication credentials. This unauthorized access potentially exposed names, email addresses, and chat histories of thousands of individuals. While Nikkei took immediate steps to address the breach by implementing password changes, the incident underscores the ongoing threats posed by breaches in collaboration platforms like Slack.

Cybersecurity consultant Brian Levine highlighted the increasing vulnerability when employees access company resources from unmanaged devices. Similar breaches at other organizations, such as Okta and MGM Resorts, have been attributed to unauthorized access from non-company-managed devices. The breach at Disney last year, where internal data was compromised through Slack due to unmanaged device access, further underscores the need for heightened security measures.

Erik Avakian, a technical counselor at Info-Tech Research Group, pointed out a concerning trend where attackers can bypass multi-factor authentication defenses by exploiting stolen session tokens and cookies. This method allows attackers to access private channels and chat histories without triggering authentication prompts. Such attacks emphasize the importance of proactive security measures and routine token refreshes to mitigate risks effectively.

Jeff Man, a senior information security consultant, raised questions about the overall risk management practices at Nikkei, particularly regarding the use of Slack on personal devices. The breach, in this case, was not a direct compromise of Slack but rather a result of compromised employee account authentication. This highlights the critical role of robust authentication practices and employee training in preventing data breaches.

Security consultant Stephen Boyce emphasized the need for a comprehensive zero-trust approach extending to all devices and data access points. By enforcing strict device verification, utilizing managed hardware, and controlling data access in SaaS tools, organizations can enhance their security posture against potential breaches. While bring-your-own-device (BYOD) policies remain relevant, organizations must prioritize secure workforce practices beyond company-issued assets to safeguard against similar incidents.

The Nikkei breach serves as a poignant reminder of the evolving cybersecurity landscape and the critical importance of proactive security measures in safeguarding sensitive data. By learning from incidents like this, organizations can strengthen their security protocols, protect against potential threats, and uphold the trust of their users and stakeholders.

You may also like