About 6.6 million user accounts were compromised in a recent intrusion into Times Car’s systems, the Japanese mobility service confirmed, exposing names, addresses, driver’s license images and other personal data for current and former members.
Timeline: early-month intrusion, public disclosure on September 25, access blocked September 26
Times Car told customers that a third party accessed its systems "at the beginning of the month." The company announced the incident publicly on September 25 and says it took action to block the unauthorized access on September 26. In an update issued earlier today, Times Car confirmed that the intrusion resulted in theft of user data.
Scope: 6.6 million current and former members and corporate-program accounts
The company said the compromise affects approximately 6.6 million current and former Times Car members and members of the Times Business Service corporate account program. Times Car is operated by Times Mobility, a business unit within the Park24 Group; the company reported having 4 million active members as of August 2026, offering online reservations for 84,000 vehicles and collection from 29,000 stations across all 47 Japanese prefectures.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleData exposed: identity documents, contact details, and account credentials
Times Car’s update lists the specific categories of information confirmed exposed in the breach. According to the company, the stolen data includes:
- Full name
- Department name for corporate members
- Physical address
- Date of birth
- Telephone number
- Email address
- Driver’s license information
- Identity verification document information, such as images of driver’s licenses
- Account password
- Linked service IDs
The company said passwords were stored in "a form that cannot be restored," suggesting they were encrypted or hashed, but it did not provide additional technical details. Times Car also confirmed that credit card information was not affected, and that there is currently no evidence the stolen data has been distributed online.
Company response: staged notifications and a forensic probe with external help
Times Car said it has begun a forensic investigation into the cause and scope of the incident with the assistance of an external expert. The firm will notify affected customers individually, but those notifications will be delivered in stages rather than all at once. Despite the breach, the company assured members that all services "continue to operate as normal."
In customer guidance, Times Car urged members to be cautious about communications claiming to come from the company — specifically warning against opening attachments or entering passwords and credit card details in response to emails, SMS messages, or phone calls.
What this means for end users, corporate account holders, and security teams
- End users: Current and former members should expect staged notifications from Times Car and be alert for phishing attempts using the exposed contact details. The presence of driver’s license images and identity verification documents raises the risk of identity-related fraud for those affected.
- Times Business Service corporate account holders: Corporate members whose department names and linked service IDs were exposed will need to monitor internal account access and third-party integrations tied to Times Car logins and corporate reservation workflows.
- Security teams and investigators: The company’s engagement of an external expert and its statement that passwords were stored in "a form that cannot be restored" are immediate focal points for forensic work: determining how access was obtained, whether credential storage and verification methods were compromised, and whether exfiltration can be fully accounted for.
Times Car’s disclosure leaves clear tasks in front of it: complete the external forensic investigation, deliver staged notifications to millions of affected accounts, and clarify technical details about credential storage and the attack vector. For members whose identity documents and contact data were taken, vigilance against phishing and identity misuse will be the near-term imperative; for the company, demonstrating how it will prevent a repeat and what protections it will offer affected users is now the central operational and reputational test.




