NewsCryptoJapan's FSA tells banks and crypto exchanges to drop photo-based ID checks early after Times Car breach

Japan's FSA tells banks and crypto exchanges to drop photo-based ID checks early after Times Car breach

Author: Cryptopolitan·

Key Takeaways

  • •Japan's FSA on October 9 directed banks and crypto-asset exchanges to end photo-based identity verification ahead of the April 1, 2027 effective date of the amended Act on Prevention of Transfer of Criminal ProceedsThe accelerated timetable follows a breach at Times Car, which holds roughly 70% of Japan's car-sharing market, that exposed about 1.6 million identity-verification documents among approximately 6.6 million user records, and more than 15,000 people have joined a class action against the company.
  • •The new verification approach reads IC chip data with a smartphone and matches the card's stored name, address, date of birth, and face photo against a live image of the applicant, while facial-capture checks remain in place.
  • •Crypto exchanges received the same directive as banks because the FSA treats crypto-asset exchange operators as financial institutions under its financial-sector cybersecurity guidelines.
  • •The FSA cited frontier AI's role in turning leaked ID images into impersonation material, referencing AI-assisted attacks on seven South Korean financial institutions, and asked firms to re-examine offsite onboarding checks and tighten scrutiny of third-party vendors.
Japan's FSA tells banks and crypto exchanges to drop photo-based ID checks early after Times Car breach

Japan's Financial Services Agency (FSA) on Friday, October 9, instructed banks and crypto-asset exchanges to stop requiring photographed identity documents for customer verification, moving the country toward a system that reads the chips embedded in ID cards. The directive pulls forward a transition previously scheduled to take effect on April 1, 2027.

The accelerated timetable follows a breach at Times Car, Japan's largest car-sharing service, in which roughly 1.6 million driver's license images were exposed. The leak compounded concerns the regulator had already raised about the capabilities of frontier AI. It also cut to the core weakness of the verification method now being retired: photo-based checks depend on exactly the kind of ID images that recent breaches have exposed.

End of photo-ID verification

In a notice published on its website, the FSA asked banks and crypto exchanges not to wait for the April 2027 implementation date of the amended Act on Prevention of Transfer of Criminal Proceeds, citing recent security incidents that have exposed customer data and ID images.

The most recent large-scale breach struck Times Car, which has about 5.4 million members and accounts for roughly 70% of Japan's car-sharing market. Approximately 1.6 million customer identity-verification documents were among about 6.6 million user records exposed in the incident, which surfaced roughly two weeks ago. More than 15,000 people have signed up for a class action against the company being prepared by Tokyo Bar Association lawyer Yuki Makino.

Under the current system, customers submit photos of their ID documents to complete identity verification. The replacement approach verifies identity by reading IC chip data, which the FSA considers far more effective against fraud. The chip-based method reads the data stored inside a card using a smartphone, then matches the chip's name, address, date of birth, and face photo against a live image of the applicant. Only the document-image upload step is being scrapped; methods that capture the applicant's face remain in place. Unlike a static upload, the check is anchored in the physical card itself rather than in an image of it.

Crypto exchanges received the same directive as traditional banks because the FSA treats crypto-asset exchange operators as financial institutions under its financial-sector cybersecurity guidelines. For customers, that places the identity check required to open an exchange account squarely within the scope of the switch.

The notice also recommended that banks and exchanges re-examine how they confirm document thickness and applicants' faces during offsite onboarding, and asked firms to tighten checks on third-party vendors.

Warning on frontier AI

In the October 9 notice, the FSA recalled two earlier requests: its financial-sector cybersecurity guidelines and a May 2026 request on short-term measures against "frontier AI" threats, issued jointly with the Bank of Japan (BOJ).

Frontier AI, a term for the most advanced models capable of strong reasoning and autonomy, has amplified the ability of bad actors to turn leaked ID images into impersonation material.

The threat has already materialized in the region. As Cryptopolitan reported earlier this month, seven South Korean financial institutions were attacked by AI-assisted hackers using the open-source tool ARTEX and Claude Code.

On August 6, the FSA, together with the National Police Agency, had asked all crypto-asset exchange operators, through the Japan Virtual and Crypto assets Exchange Association (JVCEA), to strengthen document authenticity checks and withdrawal limits, as Cryptopolitan reported at the time.

With the statutory April 2027 date still in place, the practical measure to watch is execution: how quickly individual banks and exchanges can move onboarding to chip reads, and how thoroughly they rework the offsite and vendor checks the notice flagged.