Times Car confirms data breach affecting 6.6 million user accounts
Times Car confirms hackers stole personal data of 6.6 million current and former members, including driver's license images; credit card data was unaffected.
Times Car, a Japanese car-sharing service operated by Times Mobility (Park24 Group), confirmed that attackers accessed its systems in early September and stole data on 6.6 million current and former members, including Times Business Service corporate accounts. Exposed data includes full names, addresses, dates of birth, phone numbers, email addresses, driver's license information and identity verification document images, irreversibly stored passwords, and linked service IDs. Credit card information was unaffected, and there is currently no evidence the stolen data has been distributed online. The company blocked the unauthorized access on September 26 and is running a forensic investigation with external experts.
- 6.6 million current and former Times Car and corporate program members affected
- Exposed: names, addresses, birth dates, phone, email, driver's license data, hashed passwords
- Credit card data unaffected; no evidence stolen data distributed online
- Unauthorized access blocked September 26; forensic investigation with external experts underway
Full article397 words · extracted from bleepingcomputer.com · click to collapse

Japanese car-sharing service Times Car has confirmed that approximately 6.6 million user accounts were compromised in a cyberattack disclosed late last week.
The company announced the incident on September 25, saying that a third party had accessed its systems at the beginning of the month. Times Car took action to block the unauthorized access on September 26.
At the time, the company said it was investigating whether the attackers accessed members' personal information, but confirmed the data theft in an update earlier today.
The company says that the intrusion affects 6.6 million current and former Times Car members, and also current and former members of the Times Business Service corporate account program.
According to the update, exposed information includes the following data:
- Full name
- Department name for corporate members
- Physical address
- Date of birth
- Telephone number
- Email address
- Driver’s license information
- Identity verification document information, such as images of driver’s licenses
- Account password
- Linked service IDs
The company said that passwords were stored in “a form that cannot be restored,” suggesting they were encrypted or hashed, although it did not provide additional details.
The investigation confirmed that credit card information remained unaffected. Currently, there is no evidence that the stolen data has been distributed online.
Times Car is a major vehicle rental and mobility service operated by Times Mobility, part of the Park24 Group.
It’s a large business with a claimed 4 million active members as of August 2026, allowing online reservations for 84,000 vehicles and collecting them from one of the 29,000 stations it operates across all 47 Japanese prefectures.
The company urged members to be cautious about emails, SMS, and phone calls claiming to come from Times Car, and to avoid opening attachments or typing passwords and credit card details.
The firm is now conducting a forensic investigation into the cause and scope of the incident with the help of an external expert.
Times Car said it would notify affected customers individually, but the notifications would be sent in stages.
Despite the cybersecurity incident, the company assured that all its services continue to operate as normal.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.