A customer places a card on a reader. The clerk no longer has to decide, only from plastic, laminate and a printed photograph, whether a government credential is what it claims to be.
From August 20, NTT Docomo will begin reading the integrated-circuit chips inside My Number cards, driving licences, residence cards and special permanent-resident certificates during selected procedures at its shops. Depending on the credential and method, the customer will enter a password or two PINs, or look toward a camera so a live photograph can be compared with the portrait stored in the chip. Authenticated name and address data can flow into the contract system instead of being typed from the card.
The counter action is small. The shift in trust is not. A convincing counterfeit can reproduce a printed name, a hologram and even a face well enough to pass a hurried visual inspection. A protected chip supplies another question: does the credential contain data and electronic evidence produced by the issuing authority, and can the person presenting it demonstrate the required control or resemblance?
Docomo links the change to forged documents, contracts made under another person’s identity and mobile devices obtained for crime, including special fraud. A line activated under false particulars can become communications infrastructure, a resale commodity or the first step in an account takeover. The reform tries to make the moment of enrollment and reissuance harder to fake.
Four credentials, three different kinds of evidence
“IC-chip verification” is not one procedure. Docomo’s announcement describes two routes for a My Number card and one facial-comparison route for each of the other credentials. The distinction matters because cryptographic authentication and face matching answer different questions.
| Credential and route | What the customer does | What the check contributes | Important boundary |
|---|---|---|---|
| My Number card · JPKI | Enters the 6–16 character password for the signing electronic certificate | Uses Japan’s public personal authentication service to confirm a valid certificate and control of its private key | No live facial comparison in this route; an expired or locked certificate or forgotten password can stop it |
| My Number card · eKYC-IC | Has a live face image compared with the portrait read from the chip | Binds the presenter to the protected government portrait more strongly than visual inspection alone | The result is probabilistic, not a mathematical proof of identity |
| Driving licence · eKYC-IC | Enters both four-digit IC PINs and completes live facial comparison | Unlocks protected licence data and compares the presenter with the chip portrait | Three consecutive wrong PIN entries can lock the chip until police reset it |
| Residence card or special permanent-resident certificate · eKYC-IC | Completes live facial comparison with the portrait read from the chip | Checks the presenter against a credential designed with IC and anti-counterfeit features | Identity matching does not by itself decide every question of status, authority or eligibility |
With JPKI—the Japanese initials for the Public Personal Authentication Service—the My Number card performs a cryptographic operation using a private key kept in the card. The relying service can check the accompanying certificate and whether it remains valid. The signing certificate contains the basic four attributes of name, address, date of birth and sex; it does not hand the service a citizen’s tax, pension or medical record. Docomo expressly says that it does not acquire or retain the 12-digit Individual Number.
The facial routes are one-to-one verification. The system is not searching a crowd or trying to identify an unknown person from a national gallery. It compares a live image with the portrait already bound to the credential the customer presented. That is narrower than surveillance, but it still requires clear rules for image capture, error handling and data retention.
Docomo also intends to populate a customer’s name and address automatically from authenticated data. That can reduce misspellings, mismatched scripts and manual entry errors. It also turns the verification terminal and the systems connected to it into high-value data infrastructure. Accuracy at the counter and security behind it are two sides of the same design.
Why a phone number became a skeleton key
A mobile subscription was once mainly a means to make a call. It is now an identity token used by banks, marketplaces, delivery services and social networks. A phone number receives password-reset links and one-time codes. It can be the recovery route for an email account that, in turn, unlocks everything else.
That is why SIM-swap fraud is more than theft of telephone service. An attacker impersonates the subscriber, persuades a carrier to issue a replacement SIM or transfer the number, and causes the victim’s handset to lose service. Calls and texts then arrive on the attacker’s device. If a bank still treats an SMS code as decisive, possession of the number can help reset credentials, defeat an account alert and move money before the victim understands why the screen says “No Service.”
Japan saw the danger sharply in 2022. Police describe a surge in SIM-swap damage that July and August. In September, the National Police Agency and the Ministry of Internal Affairs and Communications asked major carriers to strengthen in-store identity checks; the changes were completed by February 2023. Police data record 78 cases and ¥394 million in damage in 2022, then four cases and ¥34 million in 2023. Eleven cases and ¥46 million were recorded in 2024; in the first half of 2025, four cases caused ¥9 million in damage.
The fall after 2022 is evidence that procedures matter. It is not proof the attack disappeared. A forged licence, a manipulated portrait, a coerced legitimate customer, an insider or a weak process at a smaller provider can still provide an opening. Docomo’s chip step standardizes evidence at precisely the high-risk moment of SIM and eSIM issuance or reissuance.
- The criminal collects a victim’s name, phone number and account clues through phishing, leaks or social engineering.
- A forged or altered credential is used to request a replacement SIM, eSIM or number transfer.
- The victim’s handset loses service; the attacker begins receiving calls and SMS messages.
- Password resets and texted one-time codes help the attacker enter financial or shopping accounts.
- Money or goods move through mule accounts before the victim and provider contain the takeover.
A chip check is aimed especially at the second step. It cannot erase data already stolen at the first, compel a bank to use phishing-resistant authentication at the fourth, or recover funds at the fifth. Good security is a chain, and enrollment is one link.
From “ore-ore” calls to the law of the SIM
Japan’s struggle with criminal phones began before the smartphone. In the early 2000s, “ore-ore” calls—“It’s me, it’s me”—evolved into a broad family of remittance and impersonation frauds. Phones activated under false names, prepaid handsets and rented devices gave groups a disposable channel to victims and made the person behind a call difficult to trace.
The 2005 Act on Prevention of Improper Use of Mobile Phones, fully effective on April 1, 2006, required identity verification for voice-service contracts and records of the check. It also restricted unauthorized transfer. The premise was simple: a service that lets one person reach millions of strangers should not be issued without knowing who is responsible for the line.
Criminal practice moved. A phone’s identity was increasingly portable inside its subscriber identity module. A 2008 amendment explicitly tightened treatment of SIM cards and identity checks for rental phones, including record retention. The legal object was no longer only the handset. It followed the capability to connect.
By the 2020s, the boundary had moved again. A data-only SIM can carry messages, calls inside apps and command traffic without a traditional voice number. An eSIM can be issued remotely or embedded. A number can be taken over without stealing the physical phone. Fraud groups can recruit nominal subscribers, shift providers, use overseas services or communicate inside encrypted apps.
Parliament answered in 2026. An amendment passed on May 22 and was promulgated on May 29 as Act No. 25 of 2026. It expands the framework toward certain mobile data services, strengthens checks on the authority of people making corporate contracts, creates a path for subscriber information behind certain app or social-media accounts to be identified through police inquiries, and allows stronger controls on excessive multi-line contracts. Many substantive provisions take effect on a date set by Cabinet Order within one year, and detailed coverage depends on implementing rules. It would be inaccurate to describe the whole package as already operational on August 20.
1995 Police research on IC driving licences begins amid concern about sophisticated counterfeits.
2005–06 The mobile-phone improper-use law is enacted and fully takes effect.
2007 The first five prefectures begin issuing IC driving licences.
2008 Parliament tightens rules around SIM cards and rental phones.
2012 Japan’s IC-equipped residence-card system begins.
2016 My Number card issuance starts, carrying JPKI certificates.
2022 Police record 78 SIM-swap cases causing ¥394 million in damage.
2023 Stronger carrier counter procedures coincide with a fall to four cases.
March 2025 Japan launches the My Number-linked driving-licence system.
May 2026 Parliament passes the latest expansion of the mobile-abuse law.
August 20, 2026 Docomo’s chip verification begins sequentially.
Docomo’s move arrives between enactment and full implementation of the 2026 law. It is not merely compliance with a switch that flips that morning. It is an operational response to the same policy direction: the accountable subscriber must be connected more reliably to the communications capability, whether that capability lives in a handset, a removable SIM or software.
The government credential learned to defend itself
The history inside the cards is older than the reader on Docomo’s counter. Police began researching IC driving licences in 1995, when advances in printing and image processing were producing highly convincing forgeries. Amendments in 2001 enabled licence information to be recorded electronically. The first IC licences were issued in five prefectures in January 2007, followed by a national rollout. The chip strengthened anti-counterfeit protection and also allowed sensitive information such as registered domicile to disappear from the visible surface.
Two four-digit PINs protect different groups of licence data. That design adds friction to mass copying but produces an ordinary human problem: people who rarely use the numbers forget them. Three consecutive errors lock chip access until it is restored at a police facility. A control can be both protective and inconvenient; a well-run counter needs an alternative path and a respectful explanation when the rightful holder cannot proceed.
The residence-card system that began in 2012 likewise paired visible anti-counterfeit devices with an IC chip. The Immigration Services Agency provides a reader application so organizations can compare chip data with the printed surface and identify alteration. Special permanent-resident certificates also contain high-security chips. Their inclusion in Docomo’s process is not evidence that foreign residents are inherently suspect. It ensures that people whose normal government credential is a residence document can use a security method comparable to the one available to holders of Japanese licences or My Number cards.
My Number cards followed in 2016. The photograph and basic attributes are visible on the front; the 12-digit number appears on the back. The chip is deliberately not a container for a person’s complete government life. It holds the minimum data and cryptographic functions needed for defined services. The JPKI certificate lets a private or public service test a signed claim without receiving the Individual Number itself.
That password has consequences. The signing-certificate password uses six to 16 uppercase alphanumeric characters and locks after five consecutive failures. Certificates normally expire sooner than the physical card, and address or name changes can affect validity. A customer may possess genuine plastic but be unable to complete JPKI. Docomo’s second My Number route—chip portrait plus live face—therefore matters as more than convenience.
Docomo says it plans to support the My Number card held in Apple Wallet during fiscal 2026, subject to the schedule of relevant agencies. A customer could eventually use the iPhone credential with Face ID or Touch ID rather than carry the physical card. That capability is planned, not part of the August 20 launch. It also moves the trust chain again: from plastic and chip reader toward device security, wallet provisioning and biometric unlock.
What facial matching knows—and what it does not
The face check asks whether two images probably depict the same person. A threshold divides pass from fail. Set it too loose and an impostor may be accepted; set it too strict and the rightful customer may be rejected. Lighting, camera angle, image age, expression, disability, changes in appearance and the quality of the credential photograph all influence the comparison.
The U.S. National Institute of Standards and Technology has tested many commercial algorithms and found wide variation among developers, as well as demographic differences in error rates for many systems. Its lesson is not that facial recognition always works or always fails. It is that accuracy must be measured for the specific algorithm, population, camera conditions and decision threshold. NIST did not test the undisclosed Docomo implementation, so its findings cannot be used to assign this system an error rate.
That missing public detail should shape accountability. Docomo’s announcement does not identify the facial-matching supplier, publish a threshold or demographic performance, explain whether live and chip portraits are retained, describe a manual appeal for false rejection, or specify accessibility accommodations. Not every operational parameter belongs in a press release; every customer-facing biometric system nevertheless needs answers.
| Layer | The question | What the new process can improve | What still remains |
|---|---|---|---|
| Identity proofing | Who is enrolling or requesting reissuance? | Detects many forged or altered documents and binds the presenter to a credential | Coercion, corrupt insiders, legitimate nominees and sophisticated presentation attacks |
| Authentication | Does the presenter control the card, secret or face? | Adds possession plus a PIN/password or biometric comparison | Stolen secrets, false accepts, false rejects and locked credentials |
| Authorization | May this person perform this exact transaction? | Supplies cleaner identity data for the decision | Agency, succession, corporate authority and exceptions require separate evidence |
| Future conduct | How will the line be used after activation? | Creates a more accountable starting record | No identity check can predict criminal intent or stop later account compromise |
The scale of fraud—and the danger of claiming too much
Police recorded 27,758 conventional special-fraud cases in 2025, with provisional damage of ¥141.42 billion. They separately recorded 9,538 social-media investment-fraud cases with ¥127.47 billion in losses and 5,604 social-media romance-fraud cases with ¥55.22 billion. Added together, the three reported categories represent 42,900 cases and ¥324.11 billion in damage. A Diet committee summarized the investment and romance portion alone at about ¥182.7 billion and said more than 90 percent of the communication tools used to deceive victims in those categories were messaging apps or other data communications.
Those figures describe the environment in which communications accounts have become criminal infrastructure. They do not show that the losses were caused by fraudulently contracted Docomo lines, or that chip checks would have prevented every case. Many scams begin from a correctly issued account later stolen, an overseas number, a compromised social-media login or a recruited person using their real identity.
Security controls also displace pressure. If a major carrier becomes harder to exploit, criminals may try smaller providers, business accounts, data services beyond the rule, voice-over-IP accounts or human nominees. That is one reason the 2026 legislation looks beyond traditional voice service and why consistent standards matter across the market.
The larger defense must combine strong enrollment with phishing-resistant account authentication, quick alerts for SIM changes, waiting periods or extra scrutiny for risky reissuance, staff training, transaction monitoring, easy reporting and fast restoration for victims. Banks and platforms should not make an SMS code the only barrier protecting high-value accounts. A trustworthy telephone number is public infrastructure shared by carriers, governments and every service that treats it as evidence.
The questions the rollout should answer
Docomo’s August 12 release describes the mechanism and initial scope, not a public evaluation plan. A credible review should measure security gains and customer burden together. Counting blocked attempts alone would confuse forgotten PINs with criminals; counting completed checks alone would miss people who left the store unable to prove who they were.
- Coverage: the share of eligible transactions that actually use JPKI or chip-photo verification, by credential and procedure.
- Fraud: confirmed forged-document attempts, unlawful SIM reissuance and downstream account-takeover reports before and after rollout.
- Errors: false rejections, second-attempt success and human-review outcomes, without exposing attack-sensitive details.
- Equity: completion rates and waiting times across age, disability, credential type and language needs.
- Privacy: what images and chip fields are processed, where, for how long, by which vendors and under which employee permissions.
- Resilience: what happens during reader, certificate, camera or network outages and whether a secure alternative exists.
- Displacement: whether attempted abuse migrates to other transactions, provider categories or corporate contracts.
Customers also need practical clarity before reaching the counter: which procedure requires which credential; whether both driving-licence PINs are needed; how an expired or locked certificate is handled; what happens after a facial mismatch; and which non-chip documents remain acceptable for other transactions. Staff assistance is part of the security design. A confused customer speaking a password aloud or surrendering control of a credential would defeat the purpose of a stronger protocol.
Trust moves beneath the surface
The identity card has always been a compressed promise by the state: this name, this face and this legal status belong together. For most of the card’s history, the promise was judged from its surface. The official seal, typeface and photograph had to persuade a human eye.
Docomo’s change puts more of that promise beneath the surface. A chip protects the issuing authority’s data. A certificate can prove control through cryptography. A live image can be compared with the portrait at issuance. The clerk becomes less of a document detective and more of an operator of a layered identity process.
That process should block many cheap counterfeits and raise the cost of impersonation. It may make names and addresses more accurate and help protect a phone number that now opens far more than a telephone. But it cannot read motive. It cannot know whether a genuine subscriber has been recruited, threatened or paid, and it cannot prevent every later phishing attack.
The history of Japan’s mobile-fraud controls is the history of a moving target: handset, SIM, number, data account, app. The useful response is not to promise a final lock. It is to make each layer independently stronger, measure the harm that moves elsewhere and preserve a fair route for the rightful person who cannot get through.
On August 20, the visible act will last a few seconds: card, reader, password or face. Its deeper meaning is that trust in a mobile line will no longer rest only on whether a piece of plastic looks convincing. The future of identity is quieter than the fraud it tries to stop. It is a signed claim, a protected secret and a human being at a counter—and a system humble enough to know what none of them can prove alone.
Reporting Notes and Principal Sources
This article cross-checked carrier, police, legislative, identity-system and biometric sources published by August 13 at 9:52 AM Japan Standard Time. The rollout had not begun. Future procedure coverage, system behavior and the planned iPhone support may change.
- NTT Docomo: August 12 announcement, supported credentials, procedures and methods
- NTT Docomo: Identification documents and statement on the 12-digit My Number
- NTT Docomo: Identity verification and the 2006 mobile-phone law
- National Police Agency white paper: SIM-swap method and strengthened carrier checks
- National Police Agency: First-half 2025 cybercrime data, including SIM-swap cases and losses
- National Police Agency: 2025 special, investment and romance fraud statistics
- House of Representatives committee record, May 12, 2026: fraud losses, data communications and proposed law
- House of Councillors: 2026 bill history and enactment information
- e-Gov: Current text of the Act on Prevention of Improper Use of Mobile Phones
- House of Councillors: 2008 amendment covering SIM cards and rental-phone controls
- National Police Agency: Development and rollout of IC driving licences
- Tokyo Metropolitan Police: IC driving-licence PINs and lockout
- Digital Agency: My Number card functions, chip contents and safeguards
- Digital Agency: Signing-certificate password and reset procedures
- Immigration Services Agency: Residence-card chip reader and counterfeit detection
- Immigration Services Agency: IC security in special permanent-resident certificates
- U.S. National Institute of Standards and Technology: Facial-verification errors and demographic effects
