← Blog

Times Car Breach: 6.6M Accounts Exposed in Japan

Share on X

Park24 confirmed what millions of Japanese drivers already feared after last week’s first notice: roughly 6.6 million Times Car and Times Business Service accounts had personal data taken in an unauthorized access incident on the Times Car web system. The company’s September 28, 2026 update locked in the census and the field list. BleepingComputer covered the same confirmation the same day.

Times Car is Park24’s nationwide car-sharing brand — about four million active members as of August 2026, stations in all 47 prefectures. When driver’s license images leave with names, addresses, and phones, the phishing runway is long and personal.

Canonical record: https://breachhistory.com/times-car/times-car2026. Primary company notices: September 25 first report and the September 28 investigation update.

What happened

Park24’s timeline is unusually crisp for a consumer mobility breach of this size.

At about 9:07 a.m. Japan Standard Time on September 25, 2026, the company detected unauthorized external access against the Times Car web system and opened an investigation with outside specialists. By about 7:25 a.m. on September 26, Park24 said it had blocked the intrusion path, cut communications with the attack source, and confirmed that the blocked path was no longer reachable. Monitoring continues; as of the September 28 update, no new unauthorized access had been found.

The first public notice went up on September 25. At that point Park24 framed the event as possible personal-information leakage for Times Car members and former members, listed likely data types, and warned people about spoofed mail, SMS, and calls. The company already said services were running normally and that it was reporting to Japan’s Personal Information Protection Commission.

Three days later, the second report closed the biggest open question. Investigation confirmed that a third party had obtained some of the member information stored on the accessed system. The working count: about 6.6 million accounts. Scope: current and former Times Car members — including people who applied but never finished joining — plus current and former Times Business Service corporate-program members.

Detection and path blocking happened inside roughly a day. Confirmation of theft took a few more days of forensic work. Containment stopped further access; it did not un-steal the first pass.

What was exposed

Park24’s September 28 inventory is concrete. Exact fields vary by person, but the leaked set includes:

  • Full name
  • Corporate members’ department name
  • Physical address
  • Date of birth
  • Telephone number
  • Email address
  • Driver’s license information
  • Identity-verification document information, including images of driver’s licenses
  • Account passwords (stored in a form the company says cannot be restored)
  • Linked service IDs, including JR West Group’s WESTER ID and other partner IDs — nine linked services in total

Read that list as an identity kit, not a bare email dump. Name + address + date of birth + phone + email is classic Japanese account-takeover and social-engineering fuel. Driver’s license details and scanned ID images raise the stakes further: those artifacts support synthetic identity work, loan and SIM fraud scripts, and highly convincing “re-verify your Times Car membership” phishing pages that show a cropped version of your own license photo.

Corporate department names for Times Business Service members give attackers a workplace angle. A message that already knows your company, department, and mobile number lands harder than a generic “Dear customer” blast.

Linked service IDs are easy to underestimate. WESTER and the other eight partner IDs do not automatically mean those partners were breached. They do mean an attacker who has your Times Car dossier also knows which adjacent loyalty or rail-mobility accounts to name-drop in a follow-up scam. “Your WESTER link was reset after the Times Car incident — confirm here” is the kind of line that will circulate for months.

The 6.6 million figure covers current members, former members, and incomplete joiners. If you ever started a Times Car application, or you left the service years ago, do not assume you are outside the Times Car data breach census. Park24 said individual notices will go out in stages. Waiting for that email is not the same as being safe in the meantime.

What was not exposed

Park24’s clearest negative finding: credit card information was not leaked. That is meaningful for a reservation and payment-heavy car-sharing product. It is also not a blanket “financial risk is zero” statement. Attackers with name, address, phone, and license imagery can still attempt card-not-present social engineering or loan applications that never needed the Park24 vault’s card numbers.

On passwords, the company is careful. Credentials were stored in a non-restorable form. Park24 says that storage choice means the leaked password material does not create a practical risk of direct account misuse via restored plaintext. Separately, it says it has not confirmed that passwords themselves leaked in a form a third party could recognize. Treat both statements as good news with a remaining caveat: password reuse on other sites is still your problem if you typed the same string elsewhere, and phishing can still harvest a fresh Times Car password even when the stolen vault cannot be cracked offline.

As of the September 28 notice, Park24 also said it had not confirmed that the stolen information had been published to an unspecified public audience, and it had not confirmed misuse of personal information stemming from this incident. Those are point-in-time findings. Absence of a public dump at notice time is not a promise the data will never appear on a forum later.

What this is not, based on the company record: a named ransomware leak-site auction with a brandished folder tree, and not a confirmed payment-card breach. Do not graft those plot lines onto the Park24 breach narrative just because other September 2026 stories look louder.

How the attack worked

Park24 has not published a CVE-style root-cause write-up yet. The attested facts stop at unauthorized external access to the Times Car web system, detection at 9:07 a.m. on September 25, path and source communication blocked by 7:25 a.m. on September 26, and forensic work still underway with an external specialist. Recurrence-prevention measures — what was already done versus mid- and long-term fixes and timelines — are promised in a later update.

Speculating past “unauthorized access to the web system” would invent facts. The shape that does exist: an internet-facing membership stack held rich KYC-style data; an attacker reached that store; containment followed detection within about a day; exfiltration of a large member cohort was confirmed afterward.

For other Japanese mobility, parking, and sharing-economy operators, the uncomfortable lesson is not a novel malware family. It is how much high-assurance identity material a car-sharing platform must keep — license images, addresses, dates of birth — and how catastrophic a web-system compromise becomes when that inventory leaves in bulk. Times Car’s claimed scale (roughly four million active members, about 84,000 vehicles, about 29,000 stations) explains why the leaked account count can exceed the active-member marketing figure: former members and unfinished applications still live in the same systems.

Who is at risk

Start with anyone Park24 counted in the 6.6 million: Times Car members, ex-members, incomplete applicants, and Times Business Service members and ex-members. If you receive Park24’s staged individual notice, you are in scope. If you used the service in Japan and have not heard yet, stay alert — notices are rolling out in phases.

Individual Times Car members and former members

Your name, address, phone, email, date of birth, and license imagery are enough for targeted SMS and voice scams. Expect messages that cite the September 25 detection, claim your membership will be suspended, or pretend to be the 0120 inquiry line asking you to “re-upload your driver’s license.” Real Park24 support will not ask you to paste a password or card number into a cold message.

People who only started an application

Incomplete joiners are explicitly in the census. You may have uploaded identity documents without ever driving a Times Car. That still puts license images and contact data in the leaked set for some accounts. Do not skip the phishing hygiene because you “never became a member.”

Times Business Service corporate users

Department names plus personal contact fields create workplace-targeted phishing. Attackers can impersonate facilities, travel desks, or IT asking you to re-link a corporate car-share profile after the Park24 breach. Finance and admin assistants who book vehicles for others are high-value pivots.

Holders of linked service IDs

If your Times Car account was tied to WESTER or another of the nine linked services, watch those brands too. The linked IDs were exposed from the Times Car side; that does not equal a confirmed breach at every partner. It does equal a ready-made pretext for partner-branded follow-on phishing.

Households and employers

Shared phones, family emails, and company-paid memberships widen the blast radius. A spouse or office manager can be socially engineered with details that only sound right because they came from the Times Car dump.

Industry and campaign context

Japan’s Personal Information Protection Commission sits at the center of domestic breach response when a major consumer brand loses member PII at this scale. Park24 says it is reporting to the PPC and to police while external forensics continue. That is the expected path: contain, investigate, notify regulators, notify individuals in stages, publish updates when the census or field list changes.

Car sharing sits in a KYC-heavy niche: Times Car needs driver’s license proof to put people behind a wheel, so sensitive document images concentrate in one web system. At 6.6 million accounts — larger than the ~4 million active-member marketing figure because former members and unfinished applications still live in the same databases — the Times Car breach 2026 story is a mass identity-document incident, not “another email list.”

Compare that to ransomware theater. Extortion gangs invent volume. Park24 published detection and blocking timestamps, a working account count, a field inventory, a credit-card negative finding, and a password-handling claim — usable facts for anyone asking “was I affected.”

What Park24 and regulators said

Park24’s public posture across the two notices mixes apology, containment facts, and process commitments. The company said it blocked the path and attack-source communications, continues monitoring, confirmed theft of a portion of stored member information for about 6.6 million accounts, and is running external forensic investigation while reporting to the Personal Information Protection Commission and police.

Park24 promised staged individual guidance plus further website updates if new facts appear. Recurrence-prevention details are reserved for a later report. Services continue as usual — which does not reduce identity-theft risk from data already copied.

Park24 published a 24-hour inquiry line (0120-25-8924) and a web form. Use numbers and URLs from official park24.co.jp or timescar.jp pages — not from a cold SMS.

As of September 28, there was no published administrative fine — only the breach, forensics, and the PPC and police reporting path.

What you should do

If you are a current or former Times Car or Times Business Service user in Japan — or you started an application and walked away — work this list in order.

  1. Watch for Park24’s official individual notice. Match sender domains and any portal links against the real Park24 / Times Car sites. Notices go out in stages; silence this week is not a clean bill of health.
  2. Change your Times Car password anyway. Even with non-restorable storage claimed, rotate the credential and anywhere you reused that password. Prefer a password manager and a unique string.
  3. Turn on MFA everywhere the Times Car app, web login, and linked partner portals allow it. Linked WESTER or other partner logins deserve the same hardening.
  4. Treat Times Car–themed phishing as live for months. Call 0120-25-8924 only from the number published on the official site, not from the message body.
  5. Do not re-upload driver’s license images from a cold link. After a breach that already took ID-document images, “please submit your license again to keep your account” is the highest-yield scam pattern.
  6. Monitor mail and SMS for loan, SIM, and delivery fraud. Name + DOB + address + license data is enough for criminals to attempt carrier or consumer-finance social engineering that never needs your Times Car password.
  7. Corporate bookers: warn travel desks and facility managers. Department-aware phishing about “fleet re-enrollment after the Park24 breach” will target people who approve vehicle spend.
  8. Review linked-service account activity. Check WESTER and other linked IDs for unexpected logins or email-change requests that cite the Times Car incident as justification.
  9. Keep the company notice when it arrives. Employers, insurers, and banks sometimes ask for proof of third-party exposure scope.
  10. Follow the canonical BreachHistory page for count or field updates. Start at /times-car/times-car2026 if Park24 revises the 6.6 million figure or the exposed-data list after forensics deepen.

Phishing patterns to expect

After a names-phones-emails-plus-license-images breach, social engineering gets personal fast. A convincing SMS might open with your real name and member context, claim the Personal Information Protection Commission ordered “mandatory identity re-verification,” and push a shortened link to a clone of the Times Car login that also asks for a fresh license photo upload. Another pattern: a voice call from someone who already knows your address and date of birth, pretends to be Times Car security, and asks you to read an SMS one-time code “to cancel fraudulent reservations.” Real support will not need you to surrender a live OTP on a cold call.

Business users should watch invoice-fraud mail that cites the Times Car data breach as the reason to “approve a new payment destination.”

Linked-ID bait will name WESTER and other partners explicitly — “reconnect within 24 hours or lose rail points” is a template worth teaching family members now.

Park24’s own warning is blunt: the company will not ask for passwords or credit card information by email, SMS, or phone. Anything that does is hostile.

What “was I affected” looks like in practice

You were likely affected if Park24 sends you the individual notice. You may still be affected if you were a member, former member, or incomplete applicant around September 2026 and have not heard yet. Prefer Park24’s channel and reputable trade press over random paste sites. The working public number remains about 6.6 million accounts; credit cards excluded; passwords non-restorable; no confirmed public dump or misuse as of September 28, 2026.

Canonical record and sources

BreachHistory indexes this verified incident at https://breachhistory.com/times-car/times-car2026: company-confirmed by Park24, about 6.6 million Times Car and Times Business Service accounts, unauthorized access detected September 25, 2026 at approximately 9:07 a.m. JST, intrusion path blocked by approximately 7:25 a.m. on September 26, rich PII and driver’s license imagery among exposed fields, credit cards not leaked, services continuing, forensic work plus PPC and police reporting underway.

Authoritative outbound sources for this write-up are Park24’s September 25 first notice, the September 28 investigation update, and BleepingComputer’s September 28 report summarizing the confirmation for English-language readers.

If Park24 or the Personal Information Protection Commission later revise the headcount or field list, the catalog should move with those statements. Until then: millions of identity-rich accounts left in late September 2026; cards stayed out; license images and contact data did not; rotate credentials, harden MFA, refuse cold license re-uploads, and verify every urgency message out of band.