{"id":981178,"date":"2026-10-05T17:30:00","date_gmt":"2026-10-05T09:30:00","guid":{"rendered":"https:\/\/ztylezman.com\/?p=981178"},"modified":"2026-10-06T07:01:41","modified_gmt":"2026-10-05T23:01:41","slug":"docomo-data-breach-nikkei","status":"publish","type":"post","link":"https:\/\/ztylezman.com\/en\/gadgets-en-2\/docomo-data-breach-nikkei\/","title":{"rendered":"Docomo data breach exposes RCS metadata, Nikkei hack"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Docomo data breach and a separate Nikkei Google Workspace account intrusion were disclosed Oct. 4 by the companies, exposing contact metadata and prompting privacy checks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Japan&#8217;s largest business newspaper, Nikkei, said some staff Google Workspace accounts were accessed illegally from late July into early August, and the company only learned about the intrusion after Google notified it in early August.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Nikkei said the intrusion may have exposed the email addresses and names of <strong>1,646<\/strong> people, and the company has not confirmed whether anyone suffered follow-on harm. Nikkei did not disclose how the accounts were broken into.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">NTT Docomo announced a separate privacy incident that affected customers who signed new contracts using mobile number portability, or MNP, at Docomo retail stores between Sept. 17 and Sept. 25.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Docomo data breach, what went wrong at stores<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Docomo said a store system error prevented an important consent screen and related information from appearing during new signups, which meant customers did not have the opportunity to opt in to rich communication services, known as RCS.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As a result, about <strong>16,000<\/strong> customer records were set to an RCS available status without consent. Docomo said RCS lets users send photos and video over a phone number, and that for 225 of those cases messages were actually exchanged and phone numbers and other data were transmitted to Google Asia Pacific.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/ztylezman.com\/wp-content\/uploads\/2026\/10\/ztylezman.com_docomo-shop-860w.jpg\" alt=\"Exterior of an NTT Docomo store with red NTT docomo logo\"\/><figcaption class=\"wp-element-caption\">Exterior of an NTT Docomo store, red NTT docomo logo visible (photo: Chacmool \/ Wikimedia Commons, CC BY-SA 4.0)<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Docomo emphasized that message contents were encrypted and that Google cannot read the encrypted content, but the company acknowledged that metadata, such as who contacted whom and when, was transmitted to Google as part of RCS handling.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Docomo said this is not the first time consent procedures failed. The company previously transferred about 340,000 user phone numbers to Amazon without user consent, a separate incident that Docomo attributed to a consent flow error.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Nikkei Google Workspace intrusion, what Nikkei reported<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Nikkei said the affected Google Workspace accounts are used for staff work email, cloud storage, and other corporate tools. The publisher said it discovered the unauthorized logins only after Google informed it, indicating the attacker remained in the accounts for more than a week.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In its notification, Nikkei said it does not yet know whether the exposed names and email addresses were used for follow-up scams or other misuse. The company said it has informed affected individuals and is reviewing logs and security settings.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/ztylezman.com\/wp-content\/uploads\/2026\/10\/ztylezman.com_nikkei-docomo-privacy-numbers-860w.jpg\" alt=\"Infographic showing Nikkei may have 1,646 exposed records and Docomo about 16,000 records sent without consent, 225 sent to Google\"\/><figcaption class=\"wp-element-caption\">Summary of privacy incidents reported in Japan<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Both incidents, disclosed on Oct. 4, highlight different risks of centralized services. In the Nikkei case, Google acted as the notifier, while in the Docomo case a carrier system error caused user consent screens not to appear and metadata to be shared.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For users and IT teams the incidents are a reminder to check account security settings. Companies that use Google Workspace should review login alerts, investigate any unusual sign-in activity, and ensure two factor authentication is enabled for staff accounts.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What users should do after the Docomo data breach<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Customers who signed up at Docomo stores between Sept. 17 and Sept. 25 should watch for individual notices from Docomo beginning Oct. 4, the carrier said. Customers concerned about shared metadata can contact Docomo support for details about what was transmitted to Google.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Readers in Hong Kong and elsewhere who use Google Workspace or RCS should confirm that multi factor authentication is active and that administrators have enabled alerting for suspicious logins, because even large organizations can depend on outside notification to learn they were breached.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For its part, Docomo said it will investigate the store system error and take steps to prevent a recurrence. Nikkei said it is cooperating with Google and reviewing its internal security procedures.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Docomo data breach and a Nikkei Google Workspace intrusion disclosed Oct. 4 exposed thousands of users&#8217; contact metadata, prompting security checks and company notices.<\/p>\n","protected":false},"author":2,"featured_media":981057,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[5012],"tags":[1740,47934,35048,47798,4591,47932,47797,25253,35265,1234,47933,37143],"class_list":["post-981178","post","type-post","status-publish","format-standard","has-post-thumbnail","category-gadgets-en-2","tag-japan","tag-account-security","tag-cybersecurity","tag-docomo","tag-google","tag-mobile-carriers","tag-nikkei","tag-privacy","tag-rcs","tag-tech","tag-user-consent","tag-workspace"],"raw_content":"<!-- wp:paragraph -->\n<p>Docomo data breach and a separate Nikkei Google Workspace account intrusion were disclosed Oct. 4 by the companies, exposing contact metadata and prompting privacy checks.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p>Japan's largest business newspaper, Nikkei, said some staff Google Workspace accounts were accessed illegally from late July into early August, and the company only learned about the intrusion after Google notified it in early August.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p>Nikkei said the intrusion may have exposed the email addresses and names of <strong>1,646<\/strong> people, and the company has not confirmed whether anyone suffered follow-on harm. Nikkei did not disclose how the accounts were broken into.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p>NTT Docomo announced a separate privacy incident that affected customers who signed new contracts using mobile number portability, or MNP, at Docomo retail stores between Sept. 17 and Sept. 25.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:heading -->\n<h2>Docomo data breach, what went wrong at stores<\/h2>\n<!-- \/wp:heading -->\n\n<!-- wp:paragraph -->\n<p>Docomo said a store system error prevented an important consent screen and related information from appearing during new signups, which meant customers did not have the opportunity to opt in to rich communication services, known as RCS.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p>As a result, about <strong>16,000<\/strong> customer records were set to an RCS available status without consent. Docomo said RCS lets users send photos and video over a phone number, and that for 225 of those cases messages were actually exchanged and phone numbers and other data were transmitted to Google Asia Pacific.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:image {\"className\":\"wp-block-image\"} -->\n<figure class=\"wp-block-image\"><img src=\"https:\/\/ztylezman.com\/wp-content\/uploads\/2026\/10\/ztylezman.com_docomo-shop-860w.jpg\" alt=\"Exterior of an NTT Docomo store with red NTT docomo logo\"\/><figcaption class=\"wp-element-caption\">Exterior of an NTT Docomo store, red NTT docomo logo visible (photo: Chacmool \/ Wikimedia Commons, CC BY-SA 4.0)<\/figcaption><\/figure>\n<!-- \/wp:image -->\n\n<!-- wp:paragraph -->\n<p>Docomo emphasized that message contents were encrypted and that Google cannot read the encrypted content, but the company acknowledged that metadata, such as who contacted whom and when, was transmitted to Google as part of RCS handling.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p>Docomo said this is not the first time consent procedures failed. The company previously transferred about 340,000 user phone numbers to Amazon without user consent, a separate incident that Docomo attributed to a consent flow error.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:heading -->\n<h2>Nikkei Google Workspace intrusion, what Nikkei reported<\/h2>\n<!-- \/wp:heading -->\n\n<!-- wp:paragraph -->\n<p>Nikkei said the affected Google Workspace accounts are used for staff work email, cloud storage, and other corporate tools. The publisher said it discovered the unauthorized logins only after Google informed it, indicating the attacker remained in the accounts for more than a week.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p>In its notification, Nikkei said it does not yet know whether the exposed names and email addresses were used for follow-up scams or other misuse. The company said it has informed affected individuals and is reviewing logs and security settings.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:image {\"className\":\"wp-block-image\"} -->\n<figure class=\"wp-block-image\"><img src=\"https:\/\/ztylezman.com\/wp-content\/uploads\/2026\/10\/ztylezman.com_nikkei-docomo-privacy-numbers-860w.jpg\" alt=\"Infographic showing Nikkei may have 1,646 exposed records and Docomo about 16,000 records sent without consent, 225 sent to Google\"\/><figcaption class=\"wp-element-caption\">Summary of privacy incidents reported in Japan<\/figcaption><\/figure>\n<!-- \/wp:image -->\n\n<!-- wp:paragraph -->\n<p>Both incidents, disclosed on Oct. 4, highlight different risks of centralized services. In the Nikkei case, Google acted as the notifier, while in the Docomo case a carrier system error caused user consent screens not to appear and metadata to be shared.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p>For users and IT teams the incidents are a reminder to check account security settings. Companies that use Google Workspace should review login alerts, investigate any unusual sign-in activity, and ensure two factor authentication is enabled for staff accounts.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:heading -->\n<h2>What users should do after the Docomo data breach<\/h2>\n<!-- \/wp:heading -->\n\n<!-- wp:paragraph -->\n<p>Customers who signed up at Docomo stores between Sept. 17 and Sept. 25 should watch for individual notices from Docomo beginning Oct. 4, the carrier said. Customers concerned about shared metadata can contact Docomo support for details about what was transmitted to Google.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p>Readers in Hong Kong and elsewhere who use Google Workspace or RCS should confirm that multi factor authentication is active and that administrators have enabled alerting for suspicious logins, because even large organizations can depend on outside notification to learn they were breached.<\/p>\n<!-- \/wp:paragraph -->\n\n<!-- wp:paragraph -->\n<p>For its part, Docomo said it will investigate the store system error and take steps to prevent a recurrence. Nikkei said it is cooperating with Google and reviewing its internal security procedures.<\/p>\n<!-- \/wp:paragraph -->","_links":{"self":[{"href":"https:\/\/ztylezman.com\/en\/wp-json\/wp\/v2\/posts\/981178","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ztylezman.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ztylezman.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ztylezman.com\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/ztylezman.com\/en\/wp-json\/wp\/v2\/comments?post=981178"}],"version-history":[{"count":1,"href":"https:\/\/ztylezman.com\/en\/wp-json\/wp\/v2\/posts\/981178\/revisions"}],"predecessor-version":[{"id":981179,"href":"https:\/\/ztylezman.com\/en\/wp-json\/wp\/v2\/posts\/981178\/revisions\/981179"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ztylezman.com\/en\/wp-json\/wp\/v2\/media\/981057"}],"wp:attachment":[{"href":"https:\/\/ztylezman.com\/en\/wp-json\/wp\/v2\/media?parent=981178"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ztylezman.com\/en\/wp-json\/wp\/v2\/categories?post=981178"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ztylezman.com\/en\/wp-json\/wp\/v2\/tags?post=981178"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}