From our other sites
The story
On September 15, NTT Docomo announced that it had shared the phone numbers and contract plan names of roughly 340,000 users with Amazon.com’s Japanese subsidiary without their consent. The affected users are some of those who signed up online between April 21 and August 20 for a phone plan that includes Amazon membership perks; the cause was a configuration error that meant the consent-confirmation notice for sharing personal data was never displayed during sign-up. Docomo says Amazon deleted the data by September 12, but on 5ch, users expressed shock that such a system for sharing phone numbers and plan names externally even existed, voiced skepticism about whether the data was “really” deleted, and repeatedly compared the incident to other companies’ data breaches and past personal-information leaks.
Published 9/16 (Wed) 0:17 AM
Yomiuri Shimbun Online
NTT Docomo revealed on the 15th that it had shared the personal information of roughly 340,000 users with Amazon.com’s Japanese subsidiary without their consent. What was shared without permission was users’ phone numbers and the names of their contracted phone plans. The cause was a configuration error on Docomo’s end, and the company says Amazon deleted the data by the 12th.
Source: news.yahoo.co.jp / Original article here
What people said
Any place offering a service that partners with an outside company to do something like this — you should assume they're sharing some kind of personal data externally.
You can't link accounts together without sharing personal info.
They probably tried to get some cloud service or AWS AI to do something and accidentally uploaded a file with personal data in it.
Yeah, that's just dumb.
That's literally me.
Though I'm pretty sure they never told Amazon my plan name.
If anything that'd be through d-Points.
You don't even need to be a Docomo member for that, so why would they need to share your plan or phone number?
SoftBank just leaks stuff outright, honestly.
I canceled SoftBank Hikari years ago and I'm still getting sales calls about it.
So these are customers who were already using both services anyway.
Doesn't seem like it did much real harm.
If this weren't a major company they probably wouldn't have bothered apologizing, disclosing it, or even asking Amazon to delete the data.
Is this some special deal just for people who've linked their Amazon account ("甘", lit. "sweet", is 5ch slang for Amazon)?
I don't use Amazon, so I'm fine.
There are 340,000 people who fit that narrow a set of conditions?
Lately I keep getting calls like "This is NTT, this is your final notice."
The funny part is they say "your NTT line gets cut off in 3 hours" one day, and then just call again the next day anyway.
This is probably related to that.
Ah, so this is promo material for that.
https://ssw.web.docomo.ne.jp/prime/
Like hell they did, lmaooo
Amazon US shouldn't have any linkage set up in the first place, I'd think.
"Can you use d-Barai on Amazon too? Benefits and setup steps explained"
https://service.smt.docomo.ne.jp/keitai_payment/corporation/shop/tips/ID96.html
Especially with Docomo, this is just business as usual, no?
You'd have to report it as often as the weather forecast before it actually sinks in.
The more services you link together,
the higher the risk of a leak keeps climbing.
Humans mess up, that's just a given.
They only announced it because it's Docomo.
I think that's right, more linked services means more leak risk.
It's convenient, sure, but trying to connect everything to everything else is asking for trouble.
Like walking down the street stark naked.
Bet the bureaucrats and cabinet ministers will still be fully dressed though.
Honestly, just personal data leaking might be the mild version. If that gets bundled with your trash-talk tweets and your history of buying adult stuff, now THAT'S a scene straight out of hell, lol
If you couldn't proceed with signing up for this bundled plan without agreeing to it (I forget the exact numbers, but I think this monthly discount might be cheaper than Amazon's own monthly rate — though Amazon's own annual payment, or even YouTube's annual plan, might actually work out cheaper than this) then sure, they should have to disclose that. But either way, the data gets shared all the same, doesn't it?
"YouTube too" should read "YouTube's" (typo fix)
My mistake. Since in Re: #1 Amazon had already deleted the data, it might have been possible to proceed with sign-up even without giving consent.
Background and Key Points of This Story
This unauthorized data sharing wasn’t the result of an outside attack — it’s attributed to a configuration error on the sign-up page for the phone plan Docomo offers in partnership with Amazon (the one with discounted membership fees), which meant the consent-confirmation text for sharing personal data never displayed. Those affected were some of the users who signed up for this plan between April 21 and August 20, and only phone numbers and contract plan names were shared; Docomo says addresses and payment information were not included. On the thread, some posts noted that this kind of business partnership isn’t unusual in itself, and that “data sharing necessary for the service” and “failing to obtain consent” are separate issues — while plenty of other voices were skeptical of taking the claim that “Amazon deleted the data” at face value. Many posts also compared the incident to other personal-data cases, such as June’s leak involving My Number cards, framing it not as an isolated scandal but as part of a broader distrust toward the risks of linking personal data with outside partners — a nuance that doesn’t come through in the article text alone.
*This article is compiled and summarized from the 5ch (Breaking News Plus) thread “[NTT Docomo] Personal Data of 340,000 Users Shared Without Consent with Amazon.com’s Japanese Subsidiary… Caused by Configuration Error.”
Leave a Reply