CSIDB logo
Incident

Times Car

Incident posture

Attack window
Sep 2026
Location
Japan
Status
Unknown
CIA posture
Available to members
Updated
2026-09-29 12:11

Linked entities

Victim
Times Car
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Times Car confirmed a cyberattack that compromised approximately 6.6 million user accounts, with unauthorized access occurring early in the month and blocked the following day. The breach exposed full names, department names for corporate members, physical addresses, dates of birth, telephone numbers, email addresses, driver’s license details, images of identity verification documents, stored passwords (hashed or encrypted), and linked service identifiers, while credit card information remained unaffected and there is no evidence the data has been disseminated online. The company, which operates a fleet of tens of thousands of vehicles across thousands of stations nationwide, is conducting a forensic investigation with external experts and will notify affected individuals in stages; its services continue to operate normally.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On September 25, 2026, Times Car announced that a third party had gained unauthorized access to its systems at the beginning of the month. The company stated that it blocked the intrusion on September 26 after detecting the activity. Initially, Times Car said it was investigating whether the attackers had accessed members' personal information. Later that day, the company confirmed that a data breach had occurred and that personal data had been exfiltrated.

The breach affected approximately 6.6 million current and former Times Car members, as well as current and former participants in the Times Business Service corporate account program. Exposed information included full names, department names for corporate members, physical addresses, dates of birth, telephone numbers, email addresses, driver’s license details, images of identity verification documents, account passwords, and linked service IDs. Times Car noted that passwords were stored in a form that cannot be restored, indicating they were encrypted or hashed, though no further technical details were provided. The investigation confirmed that credit card information remained unaffected by the intrusion. To date, there is no evidence that the stolen data has been distributed online or misused.

Times Car operates as a vehicle rental and mobility service under Times Mobility, which is part of the Park24 Group. As of August 2026, the company reported four million active members, the ability to reserve 84,000 vehicles online, and access to 29,000 stations across all 47 Japanese prefectures. Following the disclosure, Times Car advised members to be vigilant against unsolicited emails, SMS messages, and phone calls purporting to be from the company and to avoid opening attachments or entering passwords and credit card details. The firm engaged an external expert to conduct a forensic investigation into the cause and scope of the incident. Times Car stated that it would notify affected customers individually, with the notifications to be sent in stages, and emphasized that all of its services continued to operate normally despite the breach.

Sources

Sources available to members: 1 source.

CSIDB