Cybersecurity

Japan pushes banks to stop trusting ID photos after a hack exposed 1.6 million

Adrian Kessler
Add us on Google

Japan’s financial regulator is pushing banks and crypto exchanges to stop relying on the photo of a driver’s license that customers upload when they open an account online. It wants them to read the chip inside the card instead, after a hack at the car-sharing service Times Car exposed identity scans on a scale that makes a picture of an ID close to worthless as proof of who someone is.

The request lands while the government describes the country as being in a cybersecurity emergency, with a run of break-ins at railway, retail and restaurant companies leaking names, addresses and birthdates by the million. The lesson travels well beyond Japan. Anyone who has photographed a license or passport for an app is exposed in the same way: once those images are copied, a criminal can try to present them as their own, and the owner cannot change the details the way they would change a password.

Times Car, run by the parking operator Park24, has said the intruders reached about 6.6 million current and former member accounts. Around 1.6 million of those records included identity documents such as driver’s license images. Names, addresses, birthdates, phone numbers and license details are among the fields that may have been exposed, and the data of people who had already quit the service had been kept for about seven years, a detail Japan’s Personal Information Protection Commission singled out when it told companies to delete data they no longer need.

Times Car is one name on a long list. The Financial Times counted more than 20 major companies reporting attacks, and the broadcaster NHK compiled at least 18 cases of comparable scale. The restaurant chain Yakiniku King said more than 10 million customer records were copied from its reservation and rewards app. JR East, the country’s largest rail operator, lost about 1.67 million email addresses from its Eki-net booking system, and Tokyo Metro, the convenience-store chain Lawson and the Nikkei newspaper have also disclosed incidents.

Digital Minister Masaaki Taira called a crisis meeting and described an “emergency in cyberspace,” while cybersecurity minister Toshiharu Furukawa called the situation “extremely critical.” Financial services minister Satsuki Katayama said institutions should “properly implement identity verification processes, including reading integrated circuit chip data.” The industry ministry is separately asking about 1,000 industry groups, from carmakers to retailers, to check their communications equipment and systems for weak points.

No group has claimed the attacks, and investigators have not tied them to a single culprit. Japan’s computer emergency response team, JPCERT/CC, has described the techniques it is seeing: scanning for unpatched flaws, abusing internal interfaces found by taking apart companies’ mobile apps, and exploiting a known SQL injection bug in the Metabase analytics tool. Some specialists suspect AI is making these campaigns cheaper. Masaki Hiraoka of the security firm Blackpanda told the Financial Times the attacks have not been explicitly linked to AI, but that such tools remove the need for long reconnaissance and make smaller targets worth hitting. Nobuo Miwa, president of the Tokyo security company S&J, described the pattern to Reuters as “carpet bombing.”

Reading the chip is a real improvement, because the data stored on it is far harder to fake than a photo. It does nothing about what has already leaked. A name, a home address and a birthdate stay valid for years and remain useful for phishing calls and fraudulent loan applications, whichever check a bank uses. The chip method also needs a phone with NFC and a card that carries a chip, and the regulator’s message is for now a push rather than an order. Several of the breach counts are still preliminary and may change as the companies finish their investigations.

The regulator’s request, issued on October 9, asks firms to move ahead of a rule change that is already on the books: from April 1, 2027, Japan’s identity-verification framework is set to end checks based on uploaded images of documents and make reading the chip the standard method. The privacy commission plans to fold its advice on passkeys, intrusion detection and deleting unneeded data into revised guidelines due next April. Times Car first detected the intrusion on September 25, and figures from TrendAI shared with Reuters show Japan logged more cybersecurity incidents in the first nine months of this year than in all of last year.

Tags: , , , , ,

Add us on Google

Discussion

There are 0 comments.