NEWS

Times Car Confirms Data Breach Affecting 6.6 Million User Accounts

Japanese car-sharing giant Times Car confirmed 6.6M accounts breached, exposing driver's license images, DOBs, and hashed passwords.

Dylan H.

News Desk

September 28, 2026
7 min read
Times Car Confirms Data Breach Affecting 6.6 Million User Accounts

Times Car Confirms 6.6 Million Accounts Compromised

Japanese car-sharing service Times Car, operated by Times Mobility under the Park24 Group, has confirmed that a cyberattack compromised approximately 6.6 million current and former user accounts. Park24 first disclosed the intrusion on September 25, 2026, after detecting unauthorized access to the Times Car web system, and blocked the access route the following day. In an updated disclosure on September 28, the company confirmed that attackers did in fact exfiltrate members' personal information, including driver's license images, dates of birth, and account passwords — upgrading the incident from a suspected exposure to a confirmed data theft.


Incident Details

AttributeValue
CompanyPark24 Group / Times Mobility (Times Car car-sharing service)
Accounts affectedApproximately 6.6 million
Members affectedCurrent and former Times Car members, incomplete-signup applicants, and current/former Times Business Service corporate account holders
Unauthorized access detectedSeptember 25, 2026, approximately 9:05 a.m. JST
Access blockedSeptember 26, 2026
Initial disclosureSeptember 25, 2026 (possible exposure)
Confirmed disclosureSeptember 28, 2026 (confirmed data theft)
Attack vectorUnauthorized third-party access to the Times Car web system (root cause not yet detailed)
AttributionNo threat actor has been publicly identified
Service scope4 million+ active members, 84,000 vehicles, roughly 29,000 stations across all 47 Japanese prefectures
Credit card dataNot affected
Evidence of public leak or fraudNone confirmed as of disclosure

How It Happened

Detection and containment

Park24 says it detected unauthorized access to the Times Car web system at roughly 9:05 a.m. JST on September 25. The company moved to cut off the intrusion route by September 26, and says all Times Car and Times Business Service functions have continued operating normally throughout — the response focused on access containment rather than a service shutdown.

From "possible exposure" to confirmed theft

Park24's initial September 25 statement described the incident as a potential leak still under investigation. Following further forensic work with external specialists, the company issued a second, formal disclosure on September 28 confirming that member data had in fact been exfiltrated, rather than merely exposed to unauthorized access. Park24 also stated it has reported the incident to police and is continuing forensic analysis, with a further update on remediation measures to follow.

Scope of exposed data

The confirmed dataset spans both individual and corporate account holders and includes:

  • Full name and, for corporate members, department name
  • Physical address, date of birth, telephone number, and email address
  • Driver's license information, including scanned images of driver's licenses and other identity-verification documents (such as student ID images) submitted during signup
  • Account passwords — Park24 says these were stored in "a form that cannot be restored," indicating hashing rather than plaintext storage, though the company did not disclose the specific algorithm
  • Linked IDs for nine external partner services, including JR West group membership programs

Park24 confirmed that credit card information was not accessed, and that, as of the September 28 update, it has found no evidence the stolen data has been posted publicly or used for fraud.


Impact Assessment

Impact AreaDescription
Identity theft / fraud riskHigh — driver's license images and identity-document scans are prime material for identity fraud, synthetic identity creation, and know-your-customer (KYC) bypass at other services
Credential exposureModerate — passwords were hashed ("cannot be restored" per Park24), but hashed passwords can still be cracked offline if a weak algorithm or weak user passwords were used; password reuse elsewhere remains a risk
Phishing and social engineeringHigh — attackers holding names, addresses, phone numbers, emails, and dates of birth for 6.6 million people have everything needed for highly convincing targeted phishing and "urgent account verification" scams impersonating Times Car
Third-party/linked-account riskModerate — exposure of linked IDs for nine external services (including JR West group programs) creates a pivot point into unrelated accounts if those services can be socially engineered using the leaked identifiers
Financial fraudLow — Park24 confirmed credit card data was not affected, limiting direct payment-fraud exposure
Business/reputational impactSignificant — Times Car is one of Japan's largest car-sharing operators (4M+ active members, 84,000 vehicles, ~29,000 stations); a breach of this scale draws regulatory scrutiny and a formal police report has already been filed

Recommendations

For Times Car / Times Business Service members

  • Assume your identity documents may be exposed. If you submitted a driver's license or student ID image during signup, treat that document as compromised and watch for its misuse in unrelated identity-verification fraud.
  • Change your Times Car password immediately, and change it on any other service where you reused the same password, even though Park24 says the stored password could not be "restored."
  • Be alert for phishing referencing this breach, including fake "verify your account" or "password reset" messages impersonating Times Car, Times Mobility, or Park24. Do not click links in unsolicited messages — log in only through the official app or website.
  • Monitor accounts on the nine linked external services (such as JR West group membership programs) for suspicious activity, since those linked IDs were also exposed.
  • Watch for follow-up notifications from Park24, which says it will contact affected customers in stages as the forensic investigation and customer notification process continues.

For security teams and administrators elsewhere

  • Treat exposed identity-document images as high-value data, not just PII — scanned driver's licenses and student IDs enable downstream KYC-bypass fraud well beyond the original organization.
  • Audit third-party/linked-account integrations. This breach shows how identifiers tied to partner loyalty programs (JR West group, in this case) widen blast radius beyond the breached company's own user base.
  • Review web-application access logging and anomaly detection for customer-facing portals handling identity documents; Park24's ability to detect and block access within roughly 24 hours suggests monitoring was in place, but earlier detection could have reduced the exfiltration window.
  • Plan for staged breach notification. Park24's phased customer-notification approach for a 6.6-million-account incident is a practical model for organizations without the capacity to notify everyone simultaneously, provided regulators and affected users are kept informed of the timeline.

Key Takeaways

  1. Times Car confirmed roughly 6.6 million accounts were compromised, spanning current/former Times Car members and Times Business Service corporate account holders.
  2. The incident escalated from "possible exposure" to confirmed data theft between the September 25 initial disclosure and the September 28 update, following forensic investigation.
  3. Exposed data includes driver's license images and other identity documents, dates of birth, contact information, and hashed passwords — but credit card data was not affected.
  4. Nine external partner service IDs were also exposed, including JR West group membership programs, extending potential fraud risk beyond Times Car itself.
  5. No threat actor has been publicly attributed, and Park24 says it has found no evidence of public data leakage or confirmed fraud so far, but has reported the incident to police.
  6. Park24 is notifying affected customers in stages while continuing its forensic investigation, with further remediation details expected in a follow-up disclosure.

Sources