ENGLISH Contact
BUSINESS── ARTICLE 008── ── 9 MIN READ

They kept your license photo for 7 years after you quit. What Japan's Times Car breach teaches about ID checks without images

A cyberattack on Times Car, Japan's largest car-sharing service, exposed images of driver's licenses and other ID documents for about 1.6 million accounts, including former members whose images were kept for seven years. As generative AI makes forgery and attacks more sophisticated, a driver's license has become a key that also unlocks financial services. We look at how Japan is moving to chip-based ID checks, and at ways to verify identity without holding images at all.

Kaito Ogasawara, editor-in-chief of DATA WORLD, frowning at a blank ID card in an endless archive of identical cards. Text: Quit the service, and your license photo stays 7 years.
If you've ever signed up for a car-sharing app in Japan, you probably remember the ritual: photograph the front of your driver's license, then the edge, then the back, then your own face.

Those photos have now leaked in bulk. Park24, which runs Times Car — by far Japan's largest car-sharing service — says a cyberattack exposed data from up to 6.6 million accounts, and that for about 1.6 million of them, images of driver's licenses and other ID documents leaked as well. The data included people who had already cancelled, and license images had been kept for seven years after members left.

For any company that handles personal data, this is a risk that can surface anywhere. So much of today's data contains personal information, and attacks around the world are getting more sophisticated with help from generative AI. A driver's license is especially sensitive: it's also one of the keys people use to prove who they are when opening a bank account.

That's exactly why Japan has started rebuilding how identity checks work, moving away from collecting images at all. This article lays out what happened in the Times Car breach, what that shift looks like, and the alternatives that businesses holding this kind of data can adopt today.

SHORT ANSWERS

Four questions people are asking, answered up front

A driver's license has gone from a document you show to a key attackers want. ID checks are shifting to methods that verify without collecting images.

Q1What leaked?

Names, addresses, birth dates, phone numbers and more for up to about 6.6 million accounts. For about 1.6 million, images of driver's licenses, utility bills and other documents leaked too. The company says it never held credit card data.
→ PART 01

Q2Why are license images a target?

One card bundles a name, address, birth date, face and number, and it's accepted for financial ID checks. Generative AI is also making forgery and attacks easier.
→ PART 02

Q3Why were former members' images still there?

The company kept them for seven years after cancellation "to prevent impersonation and handle inquiries." Regulators ask for a log of the license number and similar details; how images are handled is left to each operator.
→ PART 03

Q4How are ID checks changing?

Japan dropped photo-upload checks for mobile phone contracts in April 2026 and will for bank accounts in April 2027, switching to reading the card's IC chip.
→ PART 04
01

1.6 million of 6.6 million accounts lost their ID images too

Here's what has been confirmed so far, in order.

Date (JST)What happened
Sept 25, around 9:07 a.m.Unauthorized access to the Times Car system detected
By 7:25 a.m., Sept 26Intrusion route and communication with the attacker cut off
Sept 28Leak of up to about 6.6 million accounts announced; reported to Japan's privacy regulator and the police
Sept 29ID document images confirmed leaked for about 1.6 million accounts; emails to those affected begin
Oct 1FAQ published; individual notices to former members begin

Sources: Park24's second update, third update and FAQ. Compiled by DATA WORLD.

The leaked data includes names, addresses, birth dates, phone numbers, email addresses and driver's license details. Passwords were stored in a form that can't be reversed, and the company says it never held credit card information. It published its first notice the day it detected the attack and reported to the regulator and police.

The 1.6 million sets of images include driver's licenses, proof-of-address documents such as utility bills, student IDs for the student plan and family documents for the family plan. In other words, images that bundle a name, address, face and birth date left the building together.

Times Car passed 4 million members in August 2026, while Japan had about 5.39 million car-sharing members in March. The dates differ, but most people who car-share in Japan are Times Car members — this is a service woven into a lot of daily lives.

How the attackers got in hasn't been disclosed. An outside forensics firm is investigating, and the company says it will announce preventive measures later. This article sticks to what has been confirmed.

02

Personal data is a global target in the age of AI

Breaches aren't a single-company story. Reports from Japanese businesses to the Personal Information Protection Commission hit a record 19,056 in fiscal 2024. According to Tokyo Shoko Research, 64.4% of leak incidents at listed companies in 2025 came from malware or unauthorized access.

The attackers' tools have changed, too. In February 2024, an underground service selling fake ID images for $15 apiece reportedly got one past a crypto exchange's online identity check. iProov, which sells identity-verification technology, reported that face-swap attacks on remote ID checks rose 704% from the first to the second half of 2023. Generative AI has made convincing faces and documents dramatically cheaper to produce.

Against that backdrop, a license image is especially sensitive. It puts a name, address, birth date, face and number on one card, and it's used to prove identity for financial transactions like opening a bank account. And unlike a password, you can't easily change your address or your face.

Japan's government had already seen the risk. In June 2024, then-digital minister Taro Kono released figures on phone lines used in phone scams in 2023: of 534 lines opened with a driver's license, 386 — 72% — used a forged license. For the government-issued My Number card, it was one in 23. Checks that only look at the card face are weak against good fakes — and that became the starting point for the change described below.

Similar leaks have happened around the world.

CaseWhat leakedBackground
Omiai (Japanese dating app, 2021)1,711,756 age-verification document images (about 60% driver's licenses)Three years of verification images were on file
Discord (chat platform, 2025)Government ID photos from about 70,000 users who appealed age checksImages remained in a support contractor's records
Tea (US safety app, 2025)About 13,000 selfies and ID imagesImages remained in an older system

What these cases share is a verification setup built on collecting and storing images. As age and identity checks spread, ID images pile up in more places. How images are collected, and how long they're kept, has become a question for every industry.

03

Why the images were still there: what's required, and what's left to operators

Why did Times Car still have former members' images? Its FAQ explains that names, addresses and birth dates are kept "for seven years under tax law and other rules," and license details and images "for seven years to prevent impersonation and handle inquiries."

The reasoning is easy to follow. If someone later says "that wasn't me who rented the car," an image shows which license was presented at sign-up. Images also help in accident and fraud investigations.

What regulators actually require is smaller. Times Car is licensed as "rental-style car sharing," which falls under a notice from Japan's Ministry of Land, Infrastructure, Transport and Tourism. That notice asks for a rental log with the driver's name, address, license type and license number, kept for two years after the rental ends. Whether to keep images, and for how long, is left to each operator.

Left: what the government notice requires (driver's name and address, license type, license number, kept for two years). Right: ID documents leaked (license images, proof-of-address documents, student IDs and family documents, kept for seven years even after cancellation).
What Japan's rental rules require, compared with the ID documents that leaked. (Chart: DATA WORLD (based on the MLIT notice and Park24's announcements))

Japan's privacy law makes protecting data and reporting breaches mandatory. On deletion, Article 22 says businesses "shall endeavor" to delete data once it's no longer needed — leaving each company to decide how long to keep data for its purposes. The EU's GDPR makes it a core principle not to keep data in identifiable form longer than necessary. Keep only what you need, only as long as you need it is becoming the global norm for handling data.

04

Japan is moving ID checks from photos to IC chips

Here's the most forward-looking part of the story. Japan is rebuilding identity checks so they're harder to fake and don't require collecting images at all.

Comparison of photo-upload ID checks (photograph the license and your face, send the images, images tend to stay on file) and IC chip checks (read the chip, verify the issuer's digital signature, receive only the data needed). Mobile phone contracts abolished the photo method in April 2026, bank accounts will in April 2027, car sharing is not covered.
Two ways to verify identity, and Japan's timeline for switching. (Chart: DATA WORLD (based on National Police Agency materials and others))

For mobile phone contracts, sending a license photo plus a selfie was abolished on April 1, 2026. Under Japan's anti-money-laundering law, which covers opening bank accounts, the same method will be abolished on April 1, 2027. The main replacement is reading the IC chip in the My Number card.

The chip carries the issuer's digital signature. Tap the card with a phone, and a machine can confirm it's genuine. Checks move from squinting at a photo to verifying a signature. For in-person checks, Japan's Digital Agency offers an app that reads the chip and spots forgeries, and since June 2025 the My Number card can live on an iPhone.

Car sharing and car rental, however, fall under neither law, so operators choose their own method. At Times Car, even members registering with the chip-based My Number driver's license read the chip with a police app and then uploaded the result as an image. For services outside these laws, this is the next upgrade waiting to be adopted.

So what can services like car sharing, which sit outside these laws, adopt? From the point of view of people who work with data, here are the options.

The first is to use chip-based checks directly. Chip data can be verified with the issuer's signature, and some methods don't require the business to hold a face image at all.

The second is to delete images once the check is done and keep only the result: when it was checked, by which method and by whom, plus the license number that has to be logged. If you need evidence for later disputes, store a hash of the image — a one-way fingerprint that can't be turned back into the picture — instead of the image itself.

The third is to receive only the answer you need. The EU has published a blueprint for age verification that passes on only "over 18: yes or no," without a name or birth date. Ask only for the answer, and the data you hold shrinks.

All three treat security not just as building higher walls, but as making what you have to protect smaller.

EDITOR'S TAKE — How DATA WORLD's editor-in-chief reads it

ID checks are moving from show-and-store to verify-and-forget

Collecting and reading data is our job at DATA WORLD too. Here are three takeaways from the point of view of people who work with data.

VIEW01

The goal of an ID check is a verified fact, not an image

What an ID check needs to produce is an answer: is this a real person with a valid license? The image was only raw material for that answer.

In the age of IC chips, that raw material isn't needed. Once a signature confirms the card is genuine, all you need to keep is the fact that you checked. People who work with data tend to keep things "just in case." But data you keep is data you have to keep protecting.

VIEW02

Holding less data is a form of security

In the AI era, attackers' tools keep improving, and higher walls alone struggle to keep up. What helps is shrinking what needs protecting.

Keep data only as long as necessary. Collect only the fields you need. Once a check is done, keep the result. Reducing the data you hold is security in itself. That applies far beyond car sharing — to every company that handles customer data.

VIEW03

Services outside the law can adopt the newest approach first

Phones and banking are moving to chip-based checks all at once because the law requires it. Services outside those laws, like car sharing and dating apps, get to choose their own methods.

That also means they can adopt the most modern approach without waiting for the law. The My Number card now fits in a phone, and reading it takes far less effort than it used to. If this breach becomes the push that makes ID checks one step more modern, both users and businesses stand to gain a lot.

SOURCES ── References

  1. Park24, “Unauthorized access to Times Car (2nd update)” (September 28, 2026) (in Japanese)
  2. Park24, “Unauthorized access to Times Car (3rd update)” (September 29, 2026) (in Japanese)
  3. Times Car, FAQ on the unauthorized access (October 1, 2026) (in Japanese)
  4. Times Car, “What happens to my personal information after I cancel?” (FAQ) (in Japanese)
  5. Times Car, “Registering with a My Number driver's license” (FAQ) (in Japanese)
  6. Times Mobility, “Times Car passes 4 million members” (August 17, 2026) (in Japanese)
  7. Foundation for Promoting Personal Mobility and Ecological Transportation, car-sharing statistics (March 2026) (in Japanese)
  8. ITmedia NEWS, why Times Car kept former members' license images for 7 years (September 30, 2026) (in Japanese)
  9. Ministry of Land, Infrastructure, Transport and Tourism, notice on rental car operations (No. 138, last amended May 31, 2022) (in Japanese)
  10. e-Gov, Act on the Protection of Personal Information (in Japanese)
  11. Personal Information Protection Commission, breach report statistics for FY2025 (July 7, 2026) (in Japanese)
  12. Personal Information Protection Commission, Annual Report FY2024 (in Japanese)
  13. Tokyo Shoko Research, data leaks at listed companies in 2025 (January 30, 2026) (in Japanese)
  14. e-Gov, Enforcement Rules of the Mobile Phone Improper Use Prevention Act (in Japanese)
  15. National Police Agency, Q&A on the amendment to the Act on Prevention of Transfer of Criminal Proceeds rules (June 2025) (in Japanese)
  16. Keitai Watch, 72% of license-based phone lines used in fraud were fakes (June 2024) (in Japanese)
  17. Nikkei, three arrested for using a coerced license photo to open a credit card (September 4, 2024) (in Japanese)
  18. ITmedia NEWS, Omiai: 1.71 million ID images possibly leaked (May 21, 2021) (in Japanese)
  19. Discord, “Update on a Security Incident Involving Third-Party Customer Service” (October 2025)
  20. TechCrunch, “Dating safety app Tea breached, exposing 72,000 user images” (July 26, 2025)
  21. GDPR Art. 5, “Principles relating to processing of personal data”
  22. OAIC, Australian Privacy Principles guidelines, Chapter 11: APP 11
  23. TRUSTDOCK, eKYC using IC chips (in Japanese)
  24. European Commission, “Commission makes available an age-verification blueprint” (July 14, 2025)
  25. iProov, “New Threat Intelligence Report Exposes the Impact of Generative AI on Remote Identity Verification” (February 7, 2024)
  26. Decrypt, “AI-Generated Fake IDs Bypass KYC at Banks and Crypto Exchanges” (February 7, 2024)
  27. Digital Agency, My Number card in-person verification app (in Japanese)
  28. Digital Agency, My Number card on iPhone (June 24, 2025) (in Japanese)
#BUSINESS#Data breach#Privacy law#Identity verification#eKYC#Driver's licenses#Times Car#Security