About 1.6 million records include identity verification documents such as driver's license images

Experts warn of secondary crimes including identity theft and fraud

An image related to a data breach. [123rf]
An image related to a data breach. [123rf]

Japan's largest car-sharing operator has suffered a data breach exposing about 6.6 million user records — including driver's license and student ID images used for identity verification — raising fears of serious secondary harm to those affected.

According to Japanese media including the Tokyo Shimbun, Park24 announced Wednesday that about 6.6 million pieces of user personal information had been leaked from Times Car, a car-sharing service operated by its subsidiary Times Mobility.

The company said it believes the data was accessed through unauthorized external intrusion. Of the leaked records, about 1.6 million are identity verification documents — including driver's license and student ID images — belonging to both current and former members.

Times Car holds roughly 70 percent of Japan's car-sharing market by vehicle count, operating more than 85,000 vehicles nationwide. It has about 5.4 million members.

The large-scale exposure of ID images is drawing particular concern. Because the leaked data goes beyond basic personal details to include documents that can be used directly to verify a person's identity, experts warn the information could be exploited for identity theft, fraud and other crimes.

Masaki Kito, a lawyer who has handled data breach cases, told the Tokyo Shimbun that leaks combining basic information such as names and addresses with identity verification documents are "extremely unusual," and expressed concern the data could be used for impersonation, stalking and other crimes. He added that personal information, once leaked, is in effect impossible to retrieve, and that detecting subsequent misuse is equally difficult.

Park24 said it has not confirmed any cases in which the leaked data has actually been misused. The company said it is continuing its investigation into the specific circumstances of the breach and the full extent of the damage.

Experts in Japan are advising affected users to remain vigilant about the risk of secondary harm over the long term. They recommend notifying credit bureaus of the breach, strengthening identity verification procedures and considering changing personal details that can be updated, such as phone numbers.

Questions have also been raised about whether the company retained ID images and other personal data beyond what was necessary. JCA-NET, a Japanese civic group, said the incident should prompt businesses to examine whether they are collecting and storing personal information in excess of what laws and regulations require.

Kito also said it is worth examining not only whether the company had adequate security measures in place to prevent unauthorized access, but also whether car-sharing operators needed to continue storing driver's license images at all.


brunch@heraldcorp.com