Japan’s Financial Services Agency on Oct. 9 issued a warning to financial institutions, telling them to stop relying on uploaded ID photos for online account opening and other non-face-to-face identity checks as soon as possible and shift to reading data from IC chips embedded in identity documents, rather than waiting until the new rule formally takes effect on April 1, 2027.
The move came after a series of recent hacking incidents in which images of driver’s licenses and other identity documents were leaked together with customer information.
Formal deadline stays in 2027, but firms were told not to wait
Under the revised enforcement rules of Japan’s Act on Prevention of Transfer of Criminal Proceeds, methods that verify identity by receiving images of ID documents will be abolished from April 1, 2027. In principle, the system will shift to verification through reading IC chip data.
In its notice, the FSA described IC chip reading as a method that is “extremely effective” in preventing illicit activity and asked institutions to respond “as quickly as possible without waiting for the enforcement date,” given current conditions.
The notice did not change the legal deadline itself. April 1, 2027 remains the official abolition date, and each operator will decide when to complete the transition.
Firms must re-check document and face-photo reviews before the switch
Before the transition is complete, the FSA said institutions conducting remote identity verification should thoroughly re-examine whether there are unnatural signs in ID document images and customer facial photos, citing increasingly sophisticated impersonation techniques.
The notice also included two cybersecurity-related requests. Firms were told to refer to an alert issued the same day by the Cabinet Secretariat’s national cybersecurity coordination office, as well as any later disclosures on the causes and methods of the attacks, and then review their own security controls again.
That review should cover third-party risk management and incident response arrangements. If shortcomings are found, firms should strengthen those areas promptly based on risk.
FSA also reiterated existing cybersecurity guidance
The agency also repeated that institutions should continue following financial-sector cybersecurity guidelines, along with previously issued short-term countermeasure requirements addressing changes in threats linked to frontier AI.
Japanese media pointed to Times Car and Nippon Rent-A-Car cases
The FSA notice did not name any specific incident. In its coverage, Japanese media outlet ITmedia cited two recent cases involving member data leaks at car-sharing service Times Car and Nippon Rent-A-Car.
In one of them, Times Car parent company Park24 said in its third notice released on Sept. 29 that about 1.6 million identity document images had been leaked. The exposed files included driver’s licenses, proof-of-address documents, student IDs used for student plans, and family members’ ID images submitted for family plans.
Crypto exchanges are also within scope
According to a summary by Japanese crypto media outlet CoinPost, the FSA’s financial-sector cybersecurity guidelines published in October 2024 classify crypto asset exchange service providers as part of the group of “financial institutions, etc.”
Exchanges are also specified business operators under the Act on Prevention of Transfer of Criminal Proceeds and must verify customer identity when opening accounts. Platforms that currently let users complete onboarding by taking smartphone photos of identity documents and selfies will later need to move to methods such as reading the IC chip on a My Number Card.

