Times Car confirms breach affecting 6.6 million user accounts
The Japanese car-sharing service confirmed on 28 September 2026 that data belonging to 6.6 million current and former members was stolen. Identity documents are among the exposed information.

Times Car, the car-sharing and vehicle rental service operated by Times Mobility, a subsidiary of the Park24 group, has confirmed that roughly 6.6 million accounts were compromised in a cyberattack. The incident was reported by Bleeping Computer on 28 September 2026, and that report is at this stage the only source for this account: everything below reflects the company’s own statements as relayed there.
An intrusion in early September, confirmed three weeks later
The company made the incident public on 25 September 2026, stating that a third party had accessed its systems earlier that month. The unauthorised access was blocked on 26 September. In its initial announcement, Times Car said it was still working to establish whether members’ personal information had been reached; an update published on 28 September confirmed that data had been stolen.
The announced scope covers current and former Times Car members, as well as current and former members of the Times Business Service corporate account programme. The service reported 4 million active members in August 2026, with online booking for 84,000 vehicles available for pickup at one of its 29,000 stations across all 47 Japanese prefectures.
What the data contained
According to the company’s update, the exposed information includes full name, service or department name for corporate members, postal address, date of birth, phone number, email address, driving licence information, information from identity verification documents — including images of driving licences — account password, and credentials for linked services.
The company states that passwords were stored in a form that cannot be restored, which suggests encryption or hashing, without further detail. Payment card data is not affected, and there is so far no indication that the stolen data has been published online.
That combination is what sets this incident apart from a leak of email addresses. A password can be changed; an image of a driving licence, paired with a date of birth and an address, remains usable for a long time — in particular for identity fraud and for fraudulent messages that are convincing precisely because the details they cite are accurate.
What Times Car is asking of its customers
The company is urging members to be cautious with emails, text messages and phone calls presenting themselves as coming from Times Car, and not to open attachments or enter passwords or banking details at their request. It says it will notify affected customers individually, but that these notifications will be sent in stages: for now, not having received a message does not mean you are unaffected.
The report does not mention a general password reset. If you have reused the same password elsewhere, that is the risk to deal with first.
An investigation still under way
Times Car is now conducting a forensic investigation into the cause and extent of the incident, with the assistance of an external expert. Services remain in normal operation.
Until that investigation concludes, the figure of 6.6 million is a statement of what has been found so far, not a final total. And for the people involved, the exposed identity documents will keep circulating long after the access itself was closed.
Sources (1)
- Times Car confirms data breach affecting 6.6 million user accountsbleepingcomputer.com
Written with AI assistance from the sources cited above, then reviewed and approved before publication by Sébastien Soulier.


