Times Car
Incident posture
Timeline
Summary
Times Car confirmed a cyberattack that compromised approximately 6.6 million user accounts, with unauthorized access occurring early in the month and blocked the following day. The breach exposed full names, department names for corporate members, physical addresses, dates of birth, telephone numbers, email addresses, driver’s license details, images of identity verification documents, stored passwords (hashed or encrypted), and linked service identifiers, while credit card information remained unaffected and there is no evidence the data has been disseminated online. The company, which operates a fleet of tens of thousands of vehicles across thousands of stations nationwide, is conducting a forensic investigation with external experts and will notify affected individuals in stages; its services continue to operate normally.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On September 25, 2026, Times Car announced that a third party had gained unauthorized access to its systems at the beginning of the month. The company stated that it blocked the intrusion on September 26 after detecting the activity. Initially, Times Car said it was investigating whether the attackers had accessed members' personal information. Later that day, the company confirmed that a data breach had occurred and that personal data had been exfiltrated.
The breach affected approximately 6.6 million current and former Times Car members, as well as current and former participants in the Times Business Service corporate account program. Exposed information included full names, department names for corporate members, physical addresses, dates of birth, telephone numbers, email addresses, driver’s license details, images of identity verification documents, account passwords, and linked service IDs. Times Car noted that passwords were stored in a form that cannot be restored, indicating they were encrypted or hashed, though no further technical details were provided. The investigation confirmed that credit card information remained unaffected by the intrusion. To date, there is no evidence that the stolen data has been distributed online or misused.
Times Car operates as a vehicle rental and mobility service under Times Mobility, which is part of the Park24 Group. As of August 2026, the company reported four million active members, the ability to reserve 84,000 vehicles online, and access to 29,000 stations across all 47 Japanese prefectures. Following the disclosure, Times Car advised members to be vigilant against unsolicited emails, SMS messages, and phone calls purporting to be from the company and to avoid opening attachments or entering passwords and credit card details. The firm engaged an external expert to conduct a forensic investigation into the cause and scope of the incident. Times Car stated that it would notify affected customers individually, with the notifications to be sent in stages, and emphasized that all of its services continued to operate normally despite the breach.
Sources
Sources available to members: 1 source.