Skip to content
Japanese Car

Japanese Car

Hackread •Deeba Ahmed • October 1, 2026

A data breach at Japanese car-sharing service Times Car has exposed information linked to 6.6 million current and former accounts, including driver’s license and identity-verification data. Times Car is operated by Times Mobility, a mobility-services company within the Park24 Group, which owns the Times brand.

Times Mobility detected unauthorized access to its Times Car web systems at 9:07 a.m. on September 25, according to Park24’s first incident response update. The company said it blocked the unauthorized-access route and communications with the attack source by September 26. The exact entry point remains under investigation.

Driver’s License Images Among Exposed Data

The affected accounts include current and former Times Car members, as well as current and former users of the Times Business Service corporate program.

As per Times Car, the exposed information varies by account and includes names, addresses, dates of birth, phone numbers, email addresses, driver’s license information, identity-verification documents, account passwords and linked service IDs. Corporate accounts could also contain department names.

A September 29 update confirmed that identity-verification information linked to 1.6 million accounts had been accessed. This included driver’s license images, utility bills used to verify addresses, student identification cards for student-plan users, and family verification documents.

The company said passwords were stored in a form that cannot be restored. Credit card information was not affected, and there is currently no evidence that the accessed information has been publicly distributed or misused.

Investigation Continues as Users Face Phishing Risk

Times Mobility is conducting a forensic investigation with an external specialist to determine the cause and scope of the incident . It has also reported the breach to Japan’s Personal Information Protection Commission and police and will affected users individually in stages. Times Car’s services remain operational.

The exposed identity information could make affected users targets for impersonation and phishing. Times Car has warned users to watch for emails, SMS messages and phone calls pretending to come from the company. It says it will not request passwords or credit card information through those channels.

The Times Car disclosure coincided with increased demand at Japan’s major credit-information agencies. On September 29, the Credit Information Center (CIC) reported difficulties obtaining reception numbers for online credit-report disclosures and self-reporting.

The following day, the Japan Credit Information Reference Center (JICC) reported errors and delays caused by heavy traffic to its smartphone app.

Japanese media reported that some people were checking whether their personal information had been misused or whether credit cards or loans had been sought in their names. Neither agency, however, has confirmed that the Times Car breach directly caused the surge in requests.

Michael Centrella, Head of Public Policy at SecurityScorecard, told Hackread.com that the exposure of identity documents creates risks that can last beyond the breach itself.

“ A password can be changed, but a copy of someone’s identity document can remain useful to criminals long after the initial incident,” Centrella said. He noted that while credit card information was not exposed and passwords were stored in a form that cannot be recovered, “those are meaningful limits, but they do not remove the risk created by the identity information that was taken.”

Centrella also pointed to the inclusion of former members and people who applied but never completed registration, saying some may not have expected Times Car to still hold their information.

“The affected accounts include former members and people who applied but never completed registration. Some of those individuals may have had no reason to think Times Car still held their information. For them, the question is not only how an attacker entered the web system, but why sensitive records from past or incomplete customer relationships were still available there.”

He added that stolen names, details and license information could make fraudulent messages or calls appear more credible.

“There is also a trust issue in what happens . Someone with a customer’s name, details, and license information could make a fraudulent message or call appear more credible. For affected customers, knowing exactly which information was taken matters more than knowing how many accounts were compromised overall.”

Extracted Entities