$SOXX $SMH $SOXL #AI #機構投資 #交易所

On October 9, Japan’s Financial Services Agency issued an alert to financial institutions, urging them not to wait until the new rules take effect on April 1, 2027, but to stop using “upload a photo of your ID” for non-face-to-face identity verification, such as opening accounts online, as soon as possible and switch to reading the ID’s IC chip. The move follows a series of recent hacking incidents in which images of identity documents, including driver’s licenses, were leaked along with customer data.

Photo uploads were scheduled to be phased out in April 2027; the FSA tells businesses, “Don’t wait”

Under the revised regulations implementing the Act on Prevention of Transfer of Criminal Proceeds, verification methods that accept images of identity documents will be discontinued from April 1, 2027, and will in principle be replaced with a standardized method of reading IC chip data. In its announcement, the FSA described reading IC chips as “extremely effective in preventing fraud” and urged institutions, in light of the current situation, to “respond as quickly as possible without waiting for the implementation date.”

This announcement does not change the statutory deadline: April 1, 2027, remains the official abolition date, and each provider can decide when to switch. Until then, when conducting non-face-to-face identity verification, the Financial Services Agency is requiring providers to thoroughly recheck images of identity documents and customers’ facial photos for anything suspicious, because identity theft techniques are becoming increasingly sophisticated.

The announcement also sets out two cybersecurity-related requirements. Providers must review their cybersecurity measures—including third-party risk management and incident response mechanisms—taking into account a warning issued that same day by the Cabinet Secretariat’s National Cybersecurity Office, as well as any subsequently disclosed information about the causes and methods of attacks. They must promptly address any shortcomings in accordance with the risks. The Financial Services Agency also reiterated that institutions should maintain their defenses in line with the financial sector’s cybersecurity guidelines and the short-term countermeasures previously called for in response to evolving threats from advanced AI.

About 1.6 million images of identity documents exposed from Times Car

The Financial Services Agency’s announcement did not name any specific incidents. In its coverage of the announcement, Japanese media outlet ITmedia cited two recent cases involving leaks of member data from car-sharing service Times Car and Nippon Rent-A-Car.

In its third announcement on September 29, Park24, the parent company of Times Car, said that images of about 1.6 million identity documents had been exposed. These included driver’s licenses, proof-of-address documents, and—under its student plan—student IDs and images of family members’ identity documents under its family plan.

Japanese cryptocurrency exchanges are also covered

According to a roundup by Japanese crypto media outlet CoinPost, the Financial Services Agency’s October 2024 cybersecurity guidelines for the financial sector classify crypto asset exchange service providers as “financial institutions, etc.” Exchanges are also designated businesses regulated under the Act on Prevention of Transfer of Criminal Proceeds, and must verify customers’ identities when they open accounts. Exchanges that currently let users open accounts by taking photos of their identity documents and selfies with a smartphone will all have to switch to methods such as reading the IC chip in a personal number card (My Number Card).

This article, “Japan’s Financial Services Agency calls for the early discontinuation of ID photo KYC and a shift to identity verification using IC chips,” first appeared on .