A new license cannot erase the leaked details
A cyberattack on Japan's Times Car service has exposed identity documents in about 1.6 million member records, prompting requests for replacement driving licenses even as police warn that reissuing the cards offers limited protection against fraud. The wider breach affected about 6.6 million current and former member accounts, according to company disclosures described in reports.
Contents
- A new license cannot erase the leaked details
- How large was the exposure?
- The dates behind the response
- Why replacement requests are growing
- What reissuing a license actually changes
- Why banks are being urged to read card chips
- A broader wave of attacks, without a proven common culprit
- What is known about the attack methods?
- What affected people should watch for
- Key Points
The immediate problem is what a replacement cannot change. Reissuing a Japanese driving license changes its photograph and only the final digit of its 12 digit number, which records the number of reissues. Names, addresses and dates of birth already copied by criminals remain exposed, and businesses checking a stolen image have no reliable way to establish that the license has since been replaced.
The National Police Agency is urging financial institutions and other businesses to strengthen identity checks and asking people to consult police promptly if they suspect misuse of their information. Separately, the Financial Services Agency asked institutions on October 9 to accelerate a switch from uploaded identity document photographs to checks that read the electronic chip inside the actual card.
That change is already scheduled under amended regulations implementing the Act on Prevention of Transfer of Criminal Proceeds. From April 1, 2027, sending photographs of identity documents will cease to be an accepted method under the affected rules for identity verification without meeting the customer in person. Chip reading will become the standard, with alternatives retained for people without suitable documents or smartphones.
How large was the exposure?
Times Car is operated by an affiliate of Park24 Co. The service detected the intrusion on September 25. Reports describe approximately 6.6 million affected accounts or leaked records, including about 1.6 million containing identity documents such as driving license images.
Those figures describe different parts of the breach, rather than competing estimates of the same total. Using the reported account counts, identity documents were present in roughly 24% of affected records, or nearly one in four. Neither figure establishes an exact count of distinct individuals, and investigations could revise the totals.
The exposed information may include names, home addresses, dates of birth, telephone numbers, email addresses and license details. A Times Car user in Fukuoka City received a notification listing his address, birth date, telephone number, email address and license image among the information disclosed.
Former customers were also affected. Their data had reportedly been retained for about seven years, bringing attention to whether companies continue storing sensitive documents after their original purpose has ended. Japan's Personal Information Protection Commission has urged businesses to delete personal information they no longer need.
The dates behind the response
The push for stronger identity checks follows a regulatory change that predates the Times Car intrusion. The breach has increased pressure to implement that change before its legal start date.
- June 2025: Amendments to the identity verification regulations were promulgated, setting a future end to the affected methods based on uploaded document images.
- September 25, 2026: Times Car detected the intrusion.
- September 29: An affected customer in Kanazawa received an email confirming that his personal information had leaked.
- October 8: National Police Agency Commissioner Yoshinobu Kusunoki addressed cybersecurity and fraud prevention at a news conference.
- October 9: The Financial Services Agency requested early adoption of identity checks using card chips.
- October 11: Reports described growing inquiries and applications for license reissues across Japan.
- April 1, 2027: The amended identity verification rules are scheduled to take effect.
The October 9 request is an appeal for faster implementation, not a new immediate prohibition on existing verification methods. Institutions still using photographs are being asked to scrutinize document and facial images carefully while preparing for the transition.
Why replacement requests are growing
Police stations and driving license centers have received numerous inquiries since the breach became public. People have asked about replacing their licenses and changing recorded information, reflecting concern that an exposed identity document could be used to impersonate them.
A license is normally reissued during its validity period for reasons such as loss, theft, damage or changes to recorded details. Prefectural public safety commissions can also approve replacement for other substantial reasons. Following the Times Car leak, nearly all offices have reportedly been accepting applications, with the risk of misuse treated as grounds for reissue.
In Ishikawa Prefecture, the driving license center has received several inquiries a day. Applications are accepted at the prefectural license center in Kanazawa and at Wajima and Suzu police stations. The reported fee is 2,600 yen for a conventional license and 1,500 yen for a My Number license, which integrates driving license information with the My Number card.
A Kanazawa man in his 30s, who had used Times Car for two years, was considering replacement after receiving the September 29 notification. At the time described in the local account, he said he had not received a detailed follow up explanation. A separate Kanazawa company with a corporate Times Car contract warned all employees by email but continued using the service.
What reissuing a license actually changes
A replacement license is not a reset of a person's exposed identity. Although its photograph and final number digit change, the remaining details on a copied document can still support an impersonation attempt. Reissue also does not retrieve or delete images already taken from a company's systems.
The distinction matters because possession of a photograph is not proof that the person submitting it possesses the original card. If a business accepts the image without sufficient further checks, issuing a newer card to the legitimate holder may do little to stop someone presenting the older image.
The Personal Information Protection Commission has warned that leaked license images could be misused to obtain credit cards, open bank accounts or arrange mobile phone contracts. These are potential forms of misuse, not evidence that every exposed document has already been used fraudulently.
No nationwide total of completed reissues or confirmed fraud linked specifically to the Times Car breach is given in the reports. The evidence establishes widespread concern and local application activity, but it does not yet measure how many people have suffered financial losses.
Why banks are being urged to read card chips
Chip verification reads electronic information from a physical identity document, such as a driving license or My Number card, instead of relying only on a photograph uploaded by an applicant. That makes a stolen image alone insufficient to complete the chip reading step.
Financial services minister Satsuki Katayama urged institutions to use the stronger checks when confirming customer identities:
properly implement identity verification processes, including reading integrated circuit chip data.
The Financial Services Agency's October 9 notice also asked institutions to review cybersecurity measures, including oversight of contractors. Its request did not identify a particular breach by name, although it followed the disclosure of the Times Car intrusion and other incidents involving identity documents.
The amended regulations retain alternatives for people who do not have an identity document with a chip or a smartphone supporting near field communication, known as NFC. NFC allows a compatible phone to communicate with a card held close to it. Remaining methods include mailing an original identity document with protections against forgery.
Reading chips addresses one route to impersonation. It does not make leaked addresses, birth dates or telephone numbers unusable, nor does it remove the need for institutions to examine suspicious applications.
A broader wave of attacks, without a proven common culprit
The Times Car breach emerged alongside disclosures affecting transport, retail and restaurant services. Reported incidents include more than 10 million customer records copied from the Yakiniku King restaurant chain's reservation and rewards app, and about 1.67 million email addresses exposed from JR East's Eki-net booking system.
Reports also describe incidents involving Tokyo Metro, Lawson and Nikkei. In Fukuoka, disclosures involved the retailer MrMax and the nimoca transport card service, while JR Kyushu said web member email addresses may have leaked. These incidents vary in the information exposed and should not be treated as equivalent to a breach containing photographed identity documents.
Digital Minister Masaaki Taira convened a crisis meeting and described the situation in these terms:
emergency in cyberspace
Cybersecurity minister Toshiharu Furukawa also addressed the severity of the situation:
extremely critical
The industry ministry has asked about 1,000 industry groups to check communications equipment and systems for weaknesses. No group has claimed responsibility for the attacks described in the broader wave, and investigators have not established a single common culprit.
What is known about the attack methods?
Japan's computer emergency response team, JPCERT/CC, has described techniques seen in recent attacks, including searches for software flaws that have not been patched, misuse of internal interfaces discovered through mobile apps, and exploitation of a known SQL injection vulnerability in the Metabase analytics tool.
SQL injection means manipulating a database request so that a vulnerable application performs unintended actions, potentially exposing stored information. The reported techniques provide context for the wider attack activity, but they do not establish which method was used against Times Car.
At Fukuoka Institute of Technology, the Information Infrastructure Center reportedly recorded nearly 9,000 blocked attack attempts during a 30 minute period. That observation illustrates the volume of hostile activity facing an individual institution. It is not a count of successful breaches or a national measure of stolen records.
Security specialists have suggested that artificial intelligence may reduce the effort required to search for targets. Masaki Hiraoka of security company Blackpanda cautioned that the attacks had not been explicitly linked to AI. Neither that possibility nor the apparent geographic origin of network traffic establishes who was responsible.
What affected people should watch for
The National Police Agency expects further scam calls and fraudulent emails impersonating businesses that have suffered breaches. Exposed contact details can make such messages more convincing, especially when a caller knows a person's name, address or service membership.
At his October 8 news conference, Commissioner Yoshinobu Kusunoki said the agency would pursue both investigations and prevention. He encouraged basic precautions, including apps that block scam calls, password updates and avoiding suspicious emails.
Authorities urge people to contact police promptly when they suspect fraud or misuse. If an unfamiliar contract or account is discovered, the Personal Information Protection Commission also advises consultation with the relevant credit card company or bank. A breach notification establishes exposure; an unexpected account, contract or transaction requires a separate response.
The next fixed deadline is April 1, 2027. Revised privacy guidance covering measures such as passkeys, intrusion detection and deletion of unnecessary data is also expected next April. Until then, the central task is shared: businesses must strengthen verification and data protection, while affected people remain alert to misuse that replacing a license cannot prevent.
Key Points
- About 6.6 million Times Car accounts were affected, including roughly 1.6 million records containing identity documents.
- Replacement licenses change the photograph and final number digit, leaving much of the exposed personal information unchanged.
- Ishikawa is accepting reissue applications, with reported fees of 2,600 yen for a conventional license and 1,500 yen for a My Number license.
- Financial institutions have been asked to adopt card chip verification before new rules take effect on April 1, 2027.
- Authorities warn of impersonation, fraudulent contracts, scam calls and fake emails, and urge prompt consultation when misuse is suspected.
- The reported attack wave has not been tied to a single culprit, and a national total of fraud caused by the Times Car breach has not been established.






