grid
Abstract circular gradient with concentric rings in blue, green, yellow, and red fading into black background.
5 min read

Times Car Data Breach Hits 6.6 Million Member Accounts

Times Car data breach
Published on
September 30, 2026

Japanese car-sharing operator Times Car has confirmed that attackers stole personal data from roughly 6.6 million member accounts. The company detected unauthorised access to its web system on 25 September and warned members the same day. A follow-up report three days later confirmed the theft. Credit card details stayed out of reach, but the Times Car data breach exposed categories that no victim can reset.

What the Times Car Data Breach Exposed

The Times Car data breach affects current and former members of the consumer car-sharing service. It also covers current and former members of the Times Business Service corporate programme. People who started an application but never finished enrolment sit inside the affected group too. Park24, the parent company that runs the service through Times Mobility, put the total at about 6.6 million accounts.

Exposed fields vary from person to person. The full list covers names, corporate department names, home addresses, dates of birth, phone numbers, and email addresses. It also includes driving licence information, identity verification documents such as licence images, account passwords, and linked service IDs. That combination hands an attacker nearly everything a company collects at onboarding.

Passwords sit in storage in a form the company calls impossible to restore, which points to hashing. Nobody has named the algorithm. Investigators found no evidence that passwords leaked in readable form, and they confirmed that credit card data stayed untouched. Nothing so far suggests the stolen records have appeared publicly or fed into fraud.

Driving Licence Images Change the Risk Calculation

Most breach notices lead with email addresses and phone numbers, which feed phishing and credential stuffing for years afterwards. The Times Car data breach includes both. But the identity verification documents sitting beside them carry a different weight. A scanned licence binds a photograph, a legal name, an address, and a birth date into one artefact.

Fraudsters can present that artefact to any service running remote identity checks. Victims can change a password in seconds and a phone number with more effort, but a licence number stays fixed until renewal. That asymmetry explains why document images command higher prices on criminal markets than raw email lists.

Japanese driving licences also work as the country's default general-purpose ID, which banks, mobile operators, and landlords all accept. Criminals holding a licence image plus the matching address and birth date have most of what a remote onboarding process asks for. Fraud built on that material surfaces months or years later, long after public attention moves on.

Nine Linked Services Widen the Blast Radius

Among the exposed fields, the linked service IDs deserve more attention than their place at the bottom of the list suggests. Park24 confirmed nine connected services and named JR West Group's WESTER membership programme among them. Those identifiers tie a Times Car account to platforms the company neither operates nor secures, extending the data breach past its own perimeter.

Account linking has become standard across Japanese mobility and loyalty ecosystems, where rail operators, parking services, and payment platforms share membership graphs to smooth the customer experience. But every link also adds a path an attacker can walk. Someone holding a linked ID plus confirmed personal details has useful material for social engineering a support desk.

Members who tied a rail, retail, or payment account to Times Car should treat it as caught up in the data breach. The operators behind those platforms suffered no intrusion of their own. Reviewing recent activity and turning on multi-factor authentication costs very little. Waiting for a notice from a company that never held the compromised records makes far less sense.

Containment Moved Fast, but the Entry Point Stays Unknown

Park24's monitoring flagged the intrusion at 09:07 on 25 September, and the investigation started immediately. By 07:25 the next morning, it had blocked the attacker's route into the system, cut communication with the attacking infrastructure, and confirmed that access was no longer possible. Roughly 22 hours from detection to confirmed lockout compares well against breaches that run undisturbed for months.

The rest of the picture stays blank. Park24 has not disclosed how the attacker reached the web system, when the intrusion began, or how long it ran. No threat group has claimed the Times Car data breach, and no extortion demand has surfaced. A forensic investigation with an external firm continues, and monitoring has picked up no further unauthorised access.

Those gaps matter for the 6.6 million people involved. Dwell time determines how much an attacker could have collected beyond the confirmed records, and the entry point determines how much exposure other Park24 systems still carry. The company has promised a later report covering both completed and planned remediation.

What Members Should Do Now

Park24 has opened a 24-hour phone line and an online enquiry form, and it plans to contact affected people in stages. Staged notification means silence over the coming weeks carries no information either way. Members should act without waiting for a letter. Anyone who reused a Times Car password elsewhere should change it on every service where it appears.

Phishing presents the most immediate threat from the Times Car data breach. Attackers holding a verified name, address, and phone number can write messages that survive casual inspection. The company has warned members to expect impersonation attempts by email, SMS, and phone. Park24 never asks for passwords or card details through those channels, which gives recipients a simple test.

For organisations on the corporate programme, the department names exposed in the Times Car data breach create a narrower but sharper problem. Knowing which department an employee sits in makes a targeted pretext far more convincing, particularly against finance and procurement staff who handle payment instructions. Security teams should brief those groups directly instead of relying on general awareness messaging.

A Breach With a Long Tail

Times Car services ran normally throughout the incident. Park24 reported the Times Car data breach to Japan's Personal Information Protection Commission and to the police within days. On procedural grounds, the response looks competent and quick. The lasting damage sits with the 6.6 million people whose identity documents now circulate in unknown hands.

Consequences will keep arriving long after the forensic report lands, because the most sensitive material taken cannot be reissued. Members who scrutinise unexpected contact and audit their linked accounts will limit what attackers can do with it. That work falls to individuals, which is the uncomfortable arithmetic of any breach involving identity documents.

For the companies holding such documents, the Times Car data breach raises a sharper question about retention. Records belonging to people who cancelled years ago still sat in the system on 25 September. So did details from applicants who never completed enrolment at all.

Subscribe to newsletter

Subscribe to receive the latest blog posts to your inbox every week.

By subscribing you agree to with our Privacy Policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.