MediumII Cyber Warfare & Critical Infrastructure28 September 2026, Monday
Times Car breach exposes licence and ID data of 6.6 million accounts
Times Mobility, part of the Park24 group, confirmed on 28 September that data from about 6.6 million accounts leaked in an unauthorised access to its car-sharing service Times Car. The leaked data include driving licence images and identity documents; credit card information was not affected.
According to the company statement carried by Impress Watch, unauthorised access to the Times Car web system was detected at 09:07 on 25 September 2026. The attacker's entry route was closed by 07:25 on 26 September, and the company confirmed there was no access after that time. The roughly 6.6 million affected accounts cover current and former Times Car members, corporate Times Business Service accounts and people who had not completed their applications. The leaked information includes names, addresses, dates of birth, telephone numbers, email addresses, and driving licence details and images. It also includes identity documents such as student cards. User IDs for 9 linked services were affected too. Passwords are stored in a form that cannot be reversed, so the risk to them is considered low.
BleepingComputer reported on 28 September that the company had about 4 million active members as of August 2026. The 6.6 million leaked accounts are therefore about 1.65 times the number of active members. The company said it was conducting a forensic investigation with 1 outside specialist and had found no trace of the data being distributed online. According to Impress Watch, the incident will be reported to the Personal Information Protection Commission and the police, and affected individuals will be notified one by one. The method of the attack and the attacker's identity could not be verified, as neither source discloses them. In the same week, on 26 September, Tokyo rail operator Keio also reported a ransomware attack.
Talay assessment
Bottom line
The gravity of the leak comes from the type of data rather than the number of accounts: driving licence images and identity documents cannot be changed like a password. A pool of 6.6 million people can therefore be used for identity fraud and targeted scams for years. Its coincidence with the Keio attack in the same week shows that Japanese service companies have a wide attack surface.
Likely effects
- Identity fraudNegative6 months+
Licence and ID images can be used in attempts to open fake accounts and bypass identity verification steps; the damage is spread over years.
- Japanese regulatory pressureUncertain1–6 months
The notification to the Personal Information Protection Commission raises the question of why former members' data were kept, and could tighten data retention rules.
- TürkiyeUncertain1–6 months
Car rental and sharing companies in Türkiye also store licence images; the incident offers a case study for the debate on deleting former members' data under the data protection law KVKK.
Possibilities, ranked
- 1Investigation continues, misuse is limited55%
The forensic investigation establishes the attack route, and no evidence emerges that the data were distributed.
Watch: Times Mobility's statement on the findings of the forensic investigation
- 2Data go on sale30%
A group claims the breach and offers the data for sale on a leak site, and a wave of fraud begins.
Watch: A Times Car listing on ransomware or leak sites
- 3Sanctions and class action15%
The regulator imposes administrative measures, and users file claims for compensation.
Watch: A recommendation or order from the Personal Information Protection Commission
Probabilities are calibrated judgement based on the sources, not measurement, and are revised as new information arrives. Not investment advice.
Market reaction
Indicators affected
- Accounts leaked▲ 6.6 million
- Active members, August 2026▲ 4 million
- Linked services affected▲ 9