Times Car Confirms Data Breach Affecting 6.6 Million Users
Japanese car-sharing giant **Times Car** has disclosed a significant cyberattack, confirming that personal data belonging to approximately 6.6 million current and former user accounts was compromised. The breach, initially identified in late September, saw unauthorized access to systems and subsequent data exfiltration, prompting an urgent forensic investigation.
Japanese mobility service provider **Times Car**, a subsidiary of **Park24 Group**, has officially confirmed a data breach impacting a staggering 6.6 million user accounts. The incident, first announced on September 25, involved unauthorized third-party access to their systems at the beginning of the month.

### Scope of the Breach
The company acted swiftly to block the unauthorized access on September 26. An initial investigation focused on determining if personal information had been accessed, with a subsequent update confirming the theft of sensitive data.
The breach affects both current and former **Times Car** members, as well as participants in the **Times Business Service** corporate account program. This represents a substantial portion of their user base, given the company's reported 4 million active members as of August 2026.
### Compromised Data Points
The stolen information is extensive and includes:
* Full name
* Department name (for corporate members)
* Physical address
* Date of birth
* Telephone number
* Email address
* Driverβs license information
* Identity verification document information (e.g., images of driverβs licenses)
* Account password
* Linked service IDs
**Times Car** stated that passwords were stored in a form that "cannot be restored," suggesting robust hashing or encryption practices. Crucially, the investigation found no evidence that credit card information was compromised, nor is there currently any indication of the stolen data being distributed online.
### Company Response and User Advice
In response to the incident, **Times Car** is conducting a thorough forensic investigation with the assistance of external cybersecurity experts to ascertain the full cause and scope of the breach.
The company has urged its members to exercise extreme caution regarding unsolicited emails, SMS messages, or phone calls claiming to be from **Times Car**. Users are advised against opening suspicious attachments or entering passwords and credit card details on unverified platforms.
Notifications to affected customers will be rolled out in stages. Despite the significant cybersecurity incident, **Times Car** has assured the public that all its services continue to operate without interruption.
**Times Car** is a prominent player in the Japanese mobility sector, boasting online reservations for 84,000 vehicles across 29,000 stations in all 47 Japanese prefectures.