Times Car Confirms 6.6 Million Accounts Compromised
Japanese car-sharing service Times Car, operated by Times Mobility under the Park24 Group, has confirmed that a cyberattack compromised approximately 6.6 million current and former user accounts. Park24 first disclosed the intrusion on September 25, 2026, after detecting unauthorized access to the Times Car web system, and blocked the access route the following day. In an updated disclosure on September 28, the company confirmed that attackers did in fact exfiltrate members' personal information, including driver's license images, dates of birth, and account passwords — upgrading the incident from a suspected exposure to a confirmed data theft.
Incident Details
| Attribute | Value |
|---|---|
| Company | Park24 Group / Times Mobility (Times Car car-sharing service) |
| Accounts affected | Approximately 6.6 million |
| Members affected | Current and former Times Car members, incomplete-signup applicants, and current/former Times Business Service corporate account holders |
| Unauthorized access detected | September 25, 2026, approximately 9:05 a.m. JST |
| Access blocked | September 26, 2026 |
| Initial disclosure | September 25, 2026 (possible exposure) |
| Confirmed disclosure | September 28, 2026 (confirmed data theft) |
| Attack vector | Unauthorized third-party access to the Times Car web system (root cause not yet detailed) |
| Attribution | No threat actor has been publicly identified |
| Service scope | 4 million+ active members, 84,000 vehicles, roughly 29,000 stations across all 47 Japanese prefectures |
| Credit card data | Not affected |
| Evidence of public leak or fraud | None confirmed as of disclosure |
How It Happened
Detection and containment
Park24 says it detected unauthorized access to the Times Car web system at roughly 9:05 a.m. JST on September 25. The company moved to cut off the intrusion route by September 26, and says all Times Car and Times Business Service functions have continued operating normally throughout — the response focused on access containment rather than a service shutdown.
From "possible exposure" to confirmed theft
Park24's initial September 25 statement described the incident as a potential leak still under investigation. Following further forensic work with external specialists, the company issued a second, formal disclosure on September 28 confirming that member data had in fact been exfiltrated, rather than merely exposed to unauthorized access. Park24 also stated it has reported the incident to police and is continuing forensic analysis, with a further update on remediation measures to follow.
Scope of exposed data
The confirmed dataset spans both individual and corporate account holders and includes:
- Full name and, for corporate members, department name
- Physical address, date of birth, telephone number, and email address
- Driver's license information, including scanned images of driver's licenses and other identity-verification documents (such as student ID images) submitted during signup
- Account passwords — Park24 says these were stored in "a form that cannot be restored," indicating hashing rather than plaintext storage, though the company did not disclose the specific algorithm
- Linked IDs for nine external partner services, including JR West group membership programs
Park24 confirmed that credit card information was not accessed, and that, as of the September 28 update, it has found no evidence the stolen data has been posted publicly or used for fraud.
Impact Assessment
| Impact Area | Description |
|---|---|
| Identity theft / fraud risk | High — driver's license images and identity-document scans are prime material for identity fraud, synthetic identity creation, and know-your-customer (KYC) bypass at other services |
| Credential exposure | Moderate — passwords were hashed ("cannot be restored" per Park24), but hashed passwords can still be cracked offline if a weak algorithm or weak user passwords were used; password reuse elsewhere remains a risk |
| Phishing and social engineering | High — attackers holding names, addresses, phone numbers, emails, and dates of birth for 6.6 million people have everything needed for highly convincing targeted phishing and "urgent account verification" scams impersonating Times Car |
| Third-party/linked-account risk | Moderate — exposure of linked IDs for nine external services (including JR West group programs) creates a pivot point into unrelated accounts if those services can be socially engineered using the leaked identifiers |
| Financial fraud | Low — Park24 confirmed credit card data was not affected, limiting direct payment-fraud exposure |
| Business/reputational impact | Significant — Times Car is one of Japan's largest car-sharing operators (4M+ active members, 84,000 vehicles, ~29,000 stations); a breach of this scale draws regulatory scrutiny and a formal police report has already been filed |
Recommendations
For Times Car / Times Business Service members
- Assume your identity documents may be exposed. If you submitted a driver's license or student ID image during signup, treat that document as compromised and watch for its misuse in unrelated identity-verification fraud.
- Change your Times Car password immediately, and change it on any other service where you reused the same password, even though Park24 says the stored password could not be "restored."
- Be alert for phishing referencing this breach, including fake "verify your account" or "password reset" messages impersonating Times Car, Times Mobility, or Park24. Do not click links in unsolicited messages — log in only through the official app or website.
- Monitor accounts on the nine linked external services (such as JR West group membership programs) for suspicious activity, since those linked IDs were also exposed.
- Watch for follow-up notifications from Park24, which says it will contact affected customers in stages as the forensic investigation and customer notification process continues.
For security teams and administrators elsewhere
- Treat exposed identity-document images as high-value data, not just PII — scanned driver's licenses and student IDs enable downstream KYC-bypass fraud well beyond the original organization.
- Audit third-party/linked-account integrations. This breach shows how identifiers tied to partner loyalty programs (JR West group, in this case) widen blast radius beyond the breached company's own user base.
- Review web-application access logging and anomaly detection for customer-facing portals handling identity documents; Park24's ability to detect and block access within roughly 24 hours suggests monitoring was in place, but earlier detection could have reduced the exfiltration window.
- Plan for staged breach notification. Park24's phased customer-notification approach for a 6.6-million-account incident is a practical model for organizations without the capacity to notify everyone simultaneously, provided regulators and affected users are kept informed of the timeline.
Key Takeaways
- Times Car confirmed roughly 6.6 million accounts were compromised, spanning current/former Times Car members and Times Business Service corporate account holders.
- The incident escalated from "possible exposure" to confirmed data theft between the September 25 initial disclosure and the September 28 update, following forensic investigation.
- Exposed data includes driver's license images and other identity documents, dates of birth, contact information, and hashed passwords — but credit card data was not affected.
- Nine external partner service IDs were also exposed, including JR West group membership programs, extending potential fraud risk beyond Times Car itself.
- No threat actor has been publicly attributed, and Park24 says it has found no evidence of public data leakage or confirmed fraud so far, but has reported the incident to police.
- Park24 is notifying affected customers in stages while continuing its forensic investigation, with further remediation details expected in a follow-up disclosure.