Home » Nikkei’s Slack breach leaks sensitive data from more than 17,000 users

Nikkei’s Slack breach leaks sensitive data from more than 17,000 users

by
2 minutes read

Nikkei’s Slack Breach: Lessons Learned for Tighter Security

In a recent development, Japanese media giant Nikkei fell victim to a security breach that compromised the sensitive data of over 17,000 users through its Slack accounts. This incident serves as a stark reminder of the perils associated with allowing personal devices access to confidential corporate information.

According to Nikkei’s official statement, the breach originated from an employee’s personal computer infected with a virus, leading to the exposure of Slack authentication credentials. This unauthorized access potentially exposed personal details, email addresses, and chat histories of thousands of individuals registered on the platform.

Cybersecurity expert Brian Levine highlighted that such breaches are becoming increasingly common, emphasizing the risks posed when employees or contractors utilize non-corporate devices to access company resources. Similar attacks on other organizations like Okta and MGM Resorts have underscored the vulnerabilities associated with unmanaged access.

Erik Avakian from Info-Tech Research Group raised concerns about the ease with which attackers can bypass Multi-Factor Authentication (MFA) defenses in such scenarios. Malware targeting employee credentials can extract Slack session tokens and cookies, allowing unauthorized access without triggering MFA prompts.

To mitigate such risks, Avakian recommended that enterprise Chief Information Security Officers (CISOs) implement procedural changes. Regularly revoking active sessions, refreshing tokens, enforcing password resets, and rotating API tokens are crucial steps to enhance security posture and prevent unauthorized access.

Jeff Man, a senior information security consultant, questioned Nikkei’s IT security protocols, particularly allowing Slack usage on personal devices. He stressed the importance of robust risk management practices to prevent compromises in employee account authentication, which can lead to broader security breaches.

Stephen Boyce, a security consultant, highlighted the vulnerability of personal devices accessing work systems, emphasizing the need for a zero-trust approach that extends beyond network security. Implementing Managed Hardware-based MFA and controlling data access in SaaS tools are vital strategies to safeguard against such breaches.

The Nikkei incident underscores the significance of enhancing security measures, advocating for comprehensive risk management strategies and the adoption of stringent access controls to protect sensitive corporate data. By learning from such breaches, organizations can fortify their defenses and uphold the integrity of their digital infrastructure.

You may also like