Banks and crypto exchanges received a notice on Friday from Japan’s Financial Services Agency (FSA) to stop requiring photographed identity documents for customer verification. Today’s notice
Banks and crypto exchanges received a notice on Friday from Japan’s Financial Services Agency (FSA) to stop requiring photographed identity documents for customer verification. Today’s notice will move the Asian country to a new system of reading the chips embedded in ID cards.
The request cut the timeline on a change previously set for April 1, 2027.
The sense of urgency was escalated after about 1.6 million driver’s license images leaked in a roughly two-week-old breach of Japan’s largest car-sharing service, Times Car. That exploit compounded an earlier FSA concern about Frontier AI’s capabilities.
Japan will no longer use photo IDs for verification
The FSA made a request for banks and crypto exchanges not to wait for the April 2027 implementation date of the amended Act on Prevention of Transfer of Criminal Proceeds, after recent security incidents that have exposed customer data and ID images .
The most recent large-scale breach hit Times Car, which has about 5.4 million members and accounts for around 70% of the entire car-sharing market in the country. 1.6 million customer identity-verification documents were among the roughly 6.6 million user records exposed during the incident.
More than 15,000 people signed up for a class action being prepared against the company by Tokyo Bar Association lawyer, Yuki Makino.
Under the current system, customers are used to sending photos of their ID documents for identity verification. In its place is a system where identity is verified by reading IC chip data, which the FSA believes is far more effective against fraud.
The IC chip method reads data stored inside a card using a smartphone, then matches the chip’s name, address, date of birth and face photo against a live image of the applicant. Only the document-image upload step is being scrapped. Methods that capture the applicant’s face remain in place.
Crypto exchanges received the same directive as traditional banks in the country because Japan’s FSA treats crypto-asset exchange operators as financial institutions under its financial-sector cybersecurity guidelines.
The full notice included a recommendation to re-examine the process that banks and exchanges use to confirm document thickness and applicants’ faces during offsite onboarding. The agency also asked to tighten checks on third-party vendors.
Japan’s FSA also warned about frontier AI
The FSA recalled two earlier requests in the October 9 notice, its financial-sector cybersecurity guidelines and a May 2026 request on short-term measures against “frontier AI” threats published with the Bank of Japan (BOJ).
Frontier AI, which refers to the most advanced models capable of strong reasoning and autonomy, has amplified the ability of bad actors to turn leaked ID images into impersonation material.
The threat has already hit Japan’s neighbor in the region. As Cryptopolitan reported earlier in the month, seven South Korean financial institutions were attacked by AI-assisted hackers using the open-source tool ARTEX and Claude Code.
On August 6, the FSA, along with the National Police Agency, asked all crypto-asset exchange operators, through the Japan Virtual and Crypto assets Exchange Association (JVCEA), to strengthen document authenticity checks and withdrawal limits.
Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.