Times Car, one of Japan's largest car-sharing services, has confirmed that attackers took personal data tied to approximately 6.6 million accounts. That includes identity-document images for approximately 1.6 million accounts, mostly driver's license scans along with proof-of-address documents, student IDs and family verification papers. A driver's license is the standard identity document in Japan, so this is a high-grade identity-fraud dataset. Affected members should expect well-crafted phishing and impersonation, and organisations that accept license images for verification should treat them as potentially compromised credentials.

What happened at Times Car

Times Car is operated by Times Mobility Co., Ltd., part of the Park24 Group. According to the company's notices, it detected unauthorized external access to the Times Car web system at 9:07 a.m. on September 25, 2026 and immediately began investigating. By 7:25 a.m. on September 26, it had blocked the intrusion path, cut communications with the attack source and confirmed that access was no longer possible. The company says continued monitoring has found no further unauthorized access.

The second report, on September 28, moved from "possible leak" to confirmed theft. Times Car said that "some member information stored in the system that was accessed without authorization was obtained by a third party," and put the number of leaked accounts at approximately 6.6 million (約660万件).

How the 6.6 million figure breaks down

The 6.6 million accounts cover:

  • Current and former Times Car members, including people who applied but never completed membership for any reason.
  • Current and former Times Business Service members.

The scope of that count is notable. On September 1, Times Car ran a campaign marking more than 4 million members. The leak total is far larger because it reaches back into former members and abandoned applications, so data retention drove the size of this breach.

Data affected

Times Car says the exposed fields differ by person, but the leaked data includes the following:

CategoryDetails (per Times Car)
Identity and contactName, address, date of birth, phone number, email address; department name for corporate members
Driver's license informationDriver's license details
Identity-verification document images (~1.6 million accounts)Driver's license images; proof-of-current-address images (such as utility bills); student ID images (student plan); family verification document images (family plan)
PasswordsStored in a non-reversible format; the company says they cannot be used to misuse customer accounts
Linked service IDsIDs for nine linked services, including JR West Group's WESTER ID membership service
Credit card dataNot leaked; the company says it does not hold credit card information

The first report, from September 25, also listed membership numbers and corporate member information among the data that may have leaked.

The company's October 1 FAQ explains why former members' data was still there. Names, addresses and dates of birth are kept for seven years under tax and other laws. Driver's license information and images are also kept for seven years, for anti-impersonation purposes and to handle inquiries.

Timeline

Date (2026, JST)Event
25 Sep, 09:07Unauthorized access to the Times Car web system detected; investigation begins
25 SepReport 1 published: possible leak of member data; report made to the Personal Information Protection Commission
26 Sep, by 07:25Intrusion path blocked, attacker communications cut, loss of access confirmed
28 SepReport 2: approximately 6.6 million accounts confirmed leaked; forensic investigation by external specialists; reports to the Personal Information Protection Commission and the police
29 SepReport 3: approximately 1.6 million accounts with leaked identity-document images; individual email notices to those members begin
1 OctFAQ published; individual notices to former members begin, plus a dedicated inquiry form for former members
~2 weeks after 29 SepFurther details of the leak promised once the external investigation reports

Root cause: not yet disclosed

Times Car has not disclosed how the attackers got in. Its notices do not identify the vulnerable component, the initial access vector, how long the attackers were present before detection, the attacker's identity, or whether there was a ransom demand. Its notices describe a forensic investigation by external specialists and say recurrence-prevention measures will be published later, separated into measures already taken and medium- to long-term measures with implementation dates. Until then, any account of the technical root cause is speculation, and we will not speculate.

What the disclosures do show is where the damage came from. Identity-document images were stored where an attacker who reached the web system could take them, and they were kept for seven years after membership ended. The company also says no public release of the data and no misuse caused by the incident has been confirmed so far.

Regulatory reporting

Times Car says it has reported the incident to Japan's Personal Information Protection Commission and to the police, and that it is notifying affected people individually. The company says its overall approach to compensation will be decided after the external investigation.

Defender takeaways

For affected members

  1. Expect emails, SMS, calls and postal mail impersonating Times Car. The company says it never asks for passwords, verification codes or credit card details by email, SMS or phone. Use only the contact details on the official Times Car site.
  2. If you reused your Times Car password elsewhere, change it on those services. Times Car says the stored passwords are non-reversible, but rotating reused passwords costs little.
  3. Watch for fraudulent accounts, loans or contracts opened in your name with a copy of your driver's license, and review linked services such as WESTER ID for unexpected activity.

For organisations that collect identity documents

  1. Treat KYC images as your highest-sensitivity data class. Once a license image is verified, consider keeping only the verification result and a minimal reference instead of the full image, where the law allows.
  2. Separate the document store from the customer web tier. Put image storage behind a dedicated service with its own credentials and an API that returns only what each workflow needs. Avoid direct object access from the web application.
  3. Alert on bulk reads. Legitimate workflows open a few documents per session. Thousands of object reads from a single identity or host should page someone.
  4. Apply retention to former members and abandoned applications. These populations made up much of the Times Car total. Review whether legal retention duties really require the image itself or only the identity record.
  5. Prepare a brand-impersonation response with pre-written customer warnings and takedown processes, because phishing that cites real stolen details follows quickly after this kind of breach.