Times Car has confirmed a data breach affecting approximately 6.6 million user accounts. The Japanese car-sharing provider says an unauthorized third party obtained member information from its web system, including contact details, driver’s-license information, and identity-verification documents for some users.
What happened in the Times Car data breach
Parent company Park24 said it detected unauthorized access to the Times Car web system at 9:07 a.m. Japan Standard Time on September 25, 2026. The company began an investigation with outside specialists and confirmed that a third party had accessed the environment.
By 7:25 a.m. on September 26, Times Car said it had blocked the intrusion path, cut communications with the attack source, and verified that the attacker could no longer connect through the identified route. The company says monitoring has not detected additional unauthorized access since those containment steps.
In a September 28 update, Park24 changed the incident from a possible exposure to a confirmed breach. Its investigation found that an attacker obtained information stored in the affected system.
What Times Car has confirmed
The breach involves approximately 6.6 million accounts. The affected population includes current and former Times Car members, people who started but did not complete enrollment, and current and former members of the Times Business Service corporate program.
The exposed data varies by person and may include:
- Full names
- Corporate department names
- Home addresses
- Dates of birth
- Telephone numbers and email addresses
- Driver’s-license information
- Identity-verification records, including driver’s-license images
- Account passwords stored in a non-reversible form
- Identifiers connected to other membership services
Times Car says credit-card information was not exposed. The company also says it has not found evidence that readable passwords were disclosed, that the stolen data has been publicly posted, or that the information has been misused.
What remains under investigation
The company has not publicly identified the attacker, described the technical method used to enter the system, or attributed the incident to a named cybercrime group. No public disclosure reviewed for this report identifies the incident as ransomware.
Park24 says an external forensic investigation is continuing to determine the cause and full impact. The company has reported the incident to Japan’s Personal Information Protection Commission and police and says it will release additional findings if the investigation identifies new facts.
Who is affected
Times Car operates a large car-sharing network across Japan. The confirmed breach affects both individual members and users associated with corporate accounts, including people who no longer use the service.
The inclusion of driver’s-license and identity-document data increases the risk of convincing impersonation attempts. Criminals may combine names, contact details, birth dates, addresses, and document information to create targeted phishing messages or fraudulent account-recovery requests.
Times Car says its services continue to operate normally and that it will notify affected people in stages.
Why this breach matters to businesses
The incident shows why companies must track sensitive information across active customers, former customers, incomplete applications, and business-account users. Data that remains stored after a relationship ends can still create breach exposure.
Small businesses using mobility, travel, or other shared-service accounts should also review who can access corporate memberships. Former employees, shared inboxes, reused passwords, and connected account identifiers can turn a vendor breach into a broader business risk.
Practical defensive actions
- Watch for impersonation attempts: Treat unexpected Times Car emails, text messages, and phone calls as suspicious. Navigate to the official website or app directly instead of using message links.
- Change reused passwords: Although Times Car says passwords were stored in a non-reversible form, users who reused the same password elsewhere should replace it on every affected account.
- Enable stronger authentication: Turn on multi-factor authentication wherever it is available, especially for email, financial, and business-administration accounts.
- Review corporate memberships: Remove former employees, verify current authorized users, and replace shared credentials with individual accounts when possible.
- Prepare for identity fraud: People whose license images or identity documents were stored should monitor financial and online accounts for unusual activity and preserve any notice received from Times Car.
- Verify support requests independently: Do not provide passwords, one-time codes, payment information, or document copies to unsolicited callers or messages.
- Minimize retained data: Businesses should review how long customer and applicant records are kept and delete information that is no longer required by law or operational need.