Breach tracker

Breach report

Times Car confirms data of about 6.6 million accounts was taken

ConfirmedDisclosed Updated JapanOtherBy Vivek Kumar
Records 6.6M accountsCause Unknown
Conceptual illustration: An anonymous car-sharing key fob beside generic driving-licence cards breaking into data fragments; a parked compact car softly blurred behind. Headline: TIMES CAR DATA EXPOSURE.

AI-generated illustration by CyberShitty. Not a photograph or a document from the organisations named.

Park24, which runs the Times Car car-sharing service in Japan, says a third party took member data including driving licence images. Card details were not leaked, it says.

What happened

Park24 detected unauthorised access to the Times Car web system at 09:07 on 25 September 2026 and disclosed it the same day. By 07:25 on 26 September it had cut off the access route and communication with the attacker, and says no further unauthorised access has been seen since.

In a second notice on 28 September, Park24 said its investigation, carried out with an outside forensic firm, confirmed that a third party had obtained member information stored on the affected system. It has reported the incident to Japan's Personal Information Protection Commission and to police. The company has not yet explained how the attacker got in.

Confirmed vs. claimed

Confirmed by Park24: about 6.6 million accounts were taken. Depending on the person, the data includes name, address, date of birth, phone number, email address, driving licence details, identity document images such as licence scans, passwords, and IDs for up to 9 linked services, including JR West's WESTER ID. Passwords were stored in a form that cannot be restored, and credit card data was not leaked, the company says.

Not seen so far: Park24 says it has found no sign the data has been published or misused. No group has claimed the attack.

Who is affected

Current and former Times Car members, people who applied but never completed sign-up, and current and former Times Business Service corporate members. Park24 says it will contact affected people individually, in stages. Services are running normally.

What to do

  • If you opened a Times Car account while living in or visiting Japan, assume your details may be included until Park24 tells you otherwise.
  • Be wary of emails, SMS and calls that claim to be from Times Car. Park24 says it never asks for passwords or card details this way.
  • A scanned licence plus your address is useful for identity fraud. Watch for accounts or loans you did not open.
  • Change any password you reused from Times Car on other sites.
  • Work through our checklist on what to do after a data breach notice.

Sources

More breaches in Japan