![]() |
| An apology notice regarding personal information leakage posted on the official website of Japanese car-sharing service Times Car. The company stated that personal data was leaked due to unauthorized external access and is providing a dedicated inquiry portal where even former members who canceled their accounts can check for potential exposure. / Tokyo Bureau Chief Choi Young-jae |
A wave of cyberattacks targeting Japanese companies has exposed driver's license images of former members who canceled their accounts and enabled the unauthorized conversion of accumulated loyalty points into gift certificates. As data leaks escalate from identity theft concerns into direct financial damages, calls are mounting for stricter data retention practices and reinforced corporate security protocols.
According to the Yomiuri Shimbun on the 7th, car-sharing operator Times Car revealed on the 28th of last month that approximately 6.6 million account-related records of current and former members were compromised. Around 1.6 million of those records included images of identification documents, including driver's licenses.
A 42-year-old female office worker in Tokyo registered with Times Car was notified on the 1st that her name, address, and driver's license details had been leaked. Two days later, an e-commerce retailer also contacted her regarding a leak of her credit card details. Distressed that she could not track where her data had ended up and fearing potential misuse through identity theft, she demanded thorough countermeasures from the companies involved.
Breaches hit other sectors as well. Discount chain operator MrMax Holdings announced on the 6th that up to 1.73 million members' personal details had been compromised. Citizen Watch disclosed that unauthorized access to a third-party vendor handling its customer inquiry forms may have leaked the personal data of roughly 100,000 individuals. This underscores how third-party contractors—alongside internal enterprise networks—have served as channels for data breaches.
![]() |
| An image illustrating cybercrime and financial damages. Amid repeated personal data breaches from corporate cyberattacks across Japan, secondary damages have also been identified, including the unauthorized exchange of member reward points into gift certificate codes. / Getty Images Bank |
Secondary damages involving the exploitation of leaked data were also identified. Survey research firm GMO Research & AI announced on the 5th that unauthorized access to its survey portal led to the external exposure of up to 948,498 members' personal records. Unauthorized redemptions of member reward points for Amazon gift certificate codes reached 611 cases, amounting to 2,869,500 yen. The company plans to fully compensate the damages.
Experts pointed out that the weaponization of artificial intelligence (AI) accelerates the speed and expands the scope of cyberattacks. Professor Katsunari Yoshioka of Yokohama National University emphasized the necessity of prompt corporate responses, noting that leveraging AI allows attackers to execute widespread assaults in a short timeframe. However, it remains unconfirmed whether the damages reported by all the affected firms were caused by AI-driven attacks.
Recommendations were also made to minimize retained personal data itself alongside bolstering defensive architectures. Cybersecurity firm LAC pointed out that because completely stopping cyberattacks is difficult, organizations should minimize data retention by promptly purging data belonging to former members or customers whose contracts have terminated. LAC also stated that in the event of a breach, companies must assess the full scope of damages—including third-party contractors—and disclose it externally.
For users, preventing additional damage is an urgent priority. Masakatsu Morii, professor emeritus at Kobe University specializing in cybersecurity, advised in the Yomiuri that anyone using the same password across other platforms should change it immediately. He also explained the need to reinforce account protection using facial or fingerprint authentication.
Another point of concern is that leaked names and transaction histories can be used to craft phishing emails that appear legitimate. Professor Morii urged users to verify claims directly through official websites or apps rather than clicking links or calling phone numbers provided in emails. He also emphasized the need to check credit card statements for any unauthorized transactions.
Choi Young-jae
1
2
3
4
5
6
7