Times Mobility announced on September 28 that its Times CAR web system suffered unauthorized access, resulting in approximately 6.6 million account records being acquired by a third party. The leaked information includes names, addresses, dates of birth, phone numbers, and email addresses, as well as identity verification document information such as driver's license details and driver's license images.

A major concern stemming from the leak of identity verification documents is the potential for impersonation to apply for various services. Driver's licenses consolidate sensitive information such as name, address, date of birth, facial photo, and license number, which could be exploited to create forged documents or bypass identity verification procedures.

However, a leaked driver's license image alone does not necessarily mean that bank accounts or credit cards can be easily opened. Current online identity verification often employs methods such as photographing the individual's face in addition to submitting identity documents, or reading the IC chip information embedded in the driver's license. Furthermore, regulations are set to become stricter from April 2027, moving towards greater utilization of IC chips.

Another significant concern is fraud. If someone contacts you, knowing your name, address, date of birth, and even driver's license details, and states that "identity verification is required," it becomes much easier to mistake it for a legitimate communication from a real company. The National Police Agency also identifies image information, such as driver's licenses, as common targets for phishing attacks.

Unlike passwords or card numbers, information such as names, dates of birth, and facial photos is difficult to change. Leaked identity verification information could potentially be reused for other scams or impersonation attempts years down the line. If a driver's license image leak is confirmed, one option is to register a "Self-Declaration Comment" with the credit information agency JICC to help prevent the misuse of one's identity.

As of now, Times Mobility states that they have not confirmed any fraudulent use stemming from this incident. Moving forward, it will be crucial not to trust someone solely because they know your name, address, and date of birth. It is advisable to develop the habit of directly opening official apps or websites for verification, rather than clicking on links in emails or SMS messages.