Skip to content
Data Breach at Times Car Exposes 6.6 Million Accounts

Data Breach at Times Car Exposes 6.6 Million Accounts

First seen 1 Oct 2026, 17:04 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 1, 2026 at 17:05 UTC
  • •6.6 million accounts affected by the Times Car data breach.
  • •Exposed data includes driver's license images and identity verification documents.
  • •Users warned to be cautious of phishing attempts following the breach.

A data breach at Times Car, a Japanese car-sharing service, has compromised information from approximately 6.6 million current and former accounts. The breach was detected on September 25, 2026, when unauthorized access to the company's web systems was identified. Times Car confirmed that personal data, including driver's license images and identity verification documents, was accessed, affecting both individual and corporate accounts. The company has stated that passwords were stored in a non-recoverable format, and credit card information was not impacted. A forensic investigation is ongoing, and affected users are being notified in stages. Users are warned to be vigilant against phishing attempts. The breach coincided with increased traffic to Japan's credit information agencies, although a direct link has not been confirmed.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-25
Unauthorized access detected
Times Car identified unauthorized access to its web systems at 9:07 a.m.
Hackread
2026-09-26
Access blocked
Times Car blocked the unauthorized access route and communication with the attack source.
Hackread
2026-09-29
Data theft confirmed
Times Car confirmed that identity-verification information linked to 1.6 million accounts had been accessed.
Hackread
2026-09-29
Increased demand at credit agencies
Japan's Credit Information Center reported difficulties due to increased requests for credit reports following the breach.
Hackread

More articles in this cluster (2)

Following this threat?

Track Park24 Group in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What information was compromised?
The breach exposed names, addresses, dates of birth, phone numbers, email addresses, driver's license information, and identity verification documents.
What should affected users do?
Affected users should monitor for phishing attempts and avoid sharing sensitive information through email or SMS.
Is credit card information at risk?
No, Times Car confirmed that credit card information was not affected by the breach.