Docomo data breach and a separate Nikkei Google Workspace account intrusion were disclosed Oct. 4 by the companies, exposing contact metadata and prompting privacy checks.
Japan’s largest business newspaper, Nikkei, said some staff Google Workspace accounts were accessed illegally from late July into early August, and the company only learned about the intrusion after Google notified it in early August.
Nikkei said the intrusion may have exposed the email addresses and names of 1,646 people, and the company has not confirmed whether anyone suffered follow-on harm. Nikkei did not disclose how the accounts were broken into.
NTT Docomo announced a separate privacy incident that affected customers who signed new contracts using mobile number portability, or MNP, at Docomo retail stores between Sept. 17 and Sept. 25.
Docomo data breach, what went wrong at stores
Docomo said a store system error prevented an important consent screen and related information from appearing during new signups, which meant customers did not have the opportunity to opt in to rich communication services, known as RCS.
As a result, about 16,000 customer records were set to an RCS available status without consent. Docomo said RCS lets users send photos and video over a phone number, and that for 225 of those cases messages were actually exchanged and phone numbers and other data were transmitted to Google Asia Pacific.

Docomo emphasized that message contents were encrypted and that Google cannot read the encrypted content, but the company acknowledged that metadata, such as who contacted whom and when, was transmitted to Google as part of RCS handling.
Docomo said this is not the first time consent procedures failed. The company previously transferred about 340,000 user phone numbers to Amazon without user consent, a separate incident that Docomo attributed to a consent flow error.
Nikkei Google Workspace intrusion, what Nikkei reported
Nikkei said the affected Google Workspace accounts are used for staff work email, cloud storage, and other corporate tools. The publisher said it discovered the unauthorized logins only after Google informed it, indicating the attacker remained in the accounts for more than a week.
In its notification, Nikkei said it does not yet know whether the exposed names and email addresses were used for follow-up scams or other misuse. The company said it has informed affected individuals and is reviewing logs and security settings.

Both incidents, disclosed on Oct. 4, highlight different risks of centralized services. In the Nikkei case, Google acted as the notifier, while in the Docomo case a carrier system error caused user consent screens not to appear and metadata to be shared.
For users and IT teams the incidents are a reminder to check account security settings. Companies that use Google Workspace should review login alerts, investigate any unusual sign-in activity, and ensure two factor authentication is enabled for staff accounts.
What users should do after the Docomo data breach
Customers who signed up at Docomo stores between Sept. 17 and Sept. 25 should watch for individual notices from Docomo beginning Oct. 4, the carrier said. Customers concerned about shared metadata can contact Docomo support for details about what was transmitted to Google.
Readers in Hong Kong and elsewhere who use Google Workspace or RCS should confirm that multi factor authentication is active and that administrators have enabled alerting for suspicious logins, because even large organizations can depend on outside notification to learn they were breached.
For its part, Docomo said it will investigate the store system error and take steps to prevent a recurrence. Nikkei said it is cooperating with Google and reviewing its internal security procedures.



