The Times Car data breach is now a confirmed identity-data incident affecting about 6.6 million accounts. In an official update published on September 28, 2026, Times Mobility said an unauthorized party obtained information from the web system behind Japan's Times Car car-sharing service, including driver license data and identity-verification documents for some users.

This is not only a password-reset story. The affected population includes current members, former members, business users, and people who started an application but never completed it. When identity records survive long after a customer relationship changes, one intrusion can create years of targeted fraud and impersonation risk.

Key Takeaway: If you ever applied for Times Car, do not assume you are outside the incident because you later canceled, left the service, or never finished enrollment.

What the Times Car data breach confirmed today

Times Car's September 28 investigation update says the company detected unauthorized access at 9:07 a.m. on September 25. It began investigating immediately and says it had blocked the access path and communications with the attack source by 7:25 a.m. on September 26.

The important new fact is confirmation of acquisition. The company says its investigation found that a third party obtained some information stored in the affected system. About 6.6 million accounts fall within the disclosed scope.

Depending on the person, exposed fields may include:

  • name and address
  • date of birth, phone number, and email address
  • company department for business members
  • driver license information
  • identity-verification documents, including driver license images
  • password data stored in a non-recoverable form
  • identifiers linked to nine outside services, including WESTER ID

PARK24, the parent company, repeated those details in its September 28 investor disclosure. It said the affected group includes active and former Times Car members, active and former Times Business Service members, and applicants who did not complete enrollment.

The company says it has confirmed that credit card information was not exposed. It also says it has found no evidence so far that the data was published broadly or misused, and the service continues to operate normally.

Those are useful boundaries, but they are not a reason to ignore the incident. "No confirmed misuse" means no misuse has been established at this stage. It does not make identity records replaceable, nor does it prevent criminals from using them later.

Key Stat: The incident covers roughly 6.6 million accounts, including records belonging to people who no longer used the service or never completed registration.

Why driver license data changes the risk

Email addresses and phone numbers are common breach material. A driver license image is different because it can support identity checks, account-recovery attempts, convincing social engineering, and applications for services that accept document-based verification.

The danger grows when fields are combined. A criminal with a name, home address, birth date, phone number, email address, and document details can create messages that look unusually credible. They may know which mobility service the person used, whether the account was business-linked, and which outside identifier may be connected.

That combination can enable several practical attack paths.

Highly targeted phishing and smishing

Attackers may impersonate Times Car, PARK24, a bank, a mobile carrier, a delivery company, or a linked service. A message that includes real identity details can feel more trustworthy than generic spam.

Expect lures about compensation, identity re-verification, a mandatory password reset, a suspended driver account, or a replacement license. The company's official notice says Times Car will not ask for passwords or credit card information through email, SMS, or phone calls.

Account recovery abuse

Many services still use biographical data as proof of identity. An attacker may combine leaked details with public records or information from older breaches to answer recovery questions, persuade a support agent, or register a new account in the victim's name.

Hexon's account recovery security guide explains why recovery paths deserve the same protection as the normal login. A strong password cannot help if a support workflow accepts exposed personal facts as sufficient proof.

Document-based impersonation

A license image can be edited, recombined, or presented during weak remote verification. Not every identity platform will accept it, and modern liveness and document-integrity checks can stop many attempts. Still, the record has a longer useful life than a card number that can be replaced quickly.

Common Mistake: Focusing only on the Times Car password. The more durable risk comes from identity data that may be reused against unrelated services.

Editorial illustration visualizing what affected times car users should do now in an enterprise cybersecurity context

What affected Times Car users should do now

You do not need to panic or respond to every unexpected message. You do need a short, evidence-based protection plan.

1. Verify notices through the official site

Open the Times Car website or app directly instead of following a link in an email or text. The official incident page lists a dedicated phone number and inquiry form. Use those channels if you need to confirm whether your record is affected.

Save legitimate notifications and note when you received them. That record can help if you later need to explain an unauthorized account, dispute a transaction, or document identity misuse.

2. Change reused passwords, not only one password

Times Car says the exposed password data was stored in a form that cannot be restored. That reduces immediate password disclosure risk, but it does not justify password reuse.

If your Times Car password was reused anywhere else, replace it on every affected account with a unique password. Start with email, banking, mobile carrier, cloud storage, and identity-provider accounts because those services can unlock other recovery paths.

Use a password manager to generate and store unique credentials. Turn on phishing-resistant multifactor authentication or passkeys where available.

3. Lock down your email and mobile account

Your inbox and phone number are central to password recovery. Review recent login history, recovery addresses, forwarding rules, trusted devices, and newly registered authentication methods.

Ask your mobile carrier about account PINs and protections against unauthorized SIM replacement. A fraudster with detailed identity information may try to move a number or persuade support staff to change account settings.

4. Watch linked accounts and credit activity

Review services connected through WESTER ID or any other identifier you used with Times Car. Look for unfamiliar sign-ins, profile changes, new payment methods, or unexpected verification prompts.

Where your country offers a credit freeze, fraud alert, or identity-monitoring option, consider using it if license or identity-document data is confirmed in your individual notice. Monitor bank and card activity even though Times Car says credit card information was not part of the breach. Identity fraud can reach financial accounts through recovery and impersonation rather than direct card theft.

5. Treat follow-up contact as potentially hostile

The first phishing wave may arrive quickly, but delayed attacks are common. Criminals can wait until public attention fades or combine this data with a later breach.

Our guide to business text-message scams shows why urgency, familiar branding, and mobile-first login pages work so well. Do not provide a password, one-time code, payment card, or document image in response to unsolicited contact.

Pro Tip: A real incident notification can still be copied into a fake message. Verify the destination, not just the wording or logo.

What businesses should tell employees and customers

Business memberships add another layer of risk. The exposed information may include a corporate department, which gives attackers context for impersonating an employer, fleet administrator, travel team, or finance contact.

Organizations that enrolled staff in Times Business Service should identify affected employees and send a concise internal notice. It should explain the confirmed data categories, the official Times Car contact path, and the types of follow-up fraud to expect.

Security teams should watch for:

  • fake fleet or travel-policy updates
  • messages requesting a new driver license image
  • account recovery attempts against corporate services
  • support calls using accurate employee and department details
  • new OAuth grants or authentication methods after a suspicious login
  • expense or payment requests framed as breach reimbursement

Do not ask employees to email identity documents back to the company. Use an approved, access-controlled process only when document collection is truly necessary.

The Gyazo data breach response guide makes a related point: a breached service can expose context that becomes valuable somewhere else. In this case, mobility membership, employer information, and identity evidence can be combined to make an unrelated attack look legitimate.

Editorial illustration visualizing the retention lesson mobility platforms cannot ignore in an enterprise cybersecurity context

The retention lesson mobility platforms cannot ignore

The affected group is broader than active customers. It includes former members and people who applied but never completed membership. That detail should force every mobility, travel, rental, and gig-economy platform to review its retention design.

Identity data is often collected for a valid reason. Car-sharing services need to verify that a driver is licensed and eligible. The security question is what happens after verification, after an application is abandoned, and after the customer leaves.

A mature retention program should answer:

  1. Which fields must be kept, and for what legal or operational purpose?
  2. Can a verification result be retained instead of a full document image?
  3. When does an incomplete application expire?
  4. What triggers deletion after account closure?
  5. Are backup, analytics, and vendor copies deleted on the same schedule?
  6. Can the company prove that deletion occurred?

The goal is not to erase records recklessly. It is to prevent "keep everything" from becoming the default. Every retained license image, linked identifier, and abandoned application expands the breach population without improving the current service.

Japan's Personal Information Protection Commission says organizations should prepare to investigate facts, notify affected people, report qualifying incidents, prevent recurrence, and publish material findings. Its breach-response resources also emphasize prompt initial reporting and a later detailed report when malicious acquisition may be involved.

Key Takeaway: Data minimization is incident containment performed in advance. Information that was safely deleted cannot be stolen in a later intrusion.

What Times Car and PARK24 still need to explain

The current disclosures establish the account count, data categories, detection timeline, initial containment, and ongoing forensic work. Important questions remain unanswered publicly.

Customers need to know:

  • which individuals had license images or other identity documents exposed
  • how long the unauthorized access remained possible
  • which system weakness or credential enabled the intrusion
  • whether linked service IDs can be abused outside Times Car
  • how former and incomplete applicant records were retained
  • what specific monitoring and identity-protection support will be offered
  • when completed remediation and retention changes will be published

The company has said it will contact affected people individually and publish prevention measures in a follow-up report. Those updates should distinguish confirmed facts from ongoing investigation and give users actions tailored to their actual data exposure.

This matters because generic reassurance does not fit a mixed dataset. A user whose email address was exposed faces a different risk from someone whose license image, birth date, address, phone number, and linked ID were all acquired.

Hexon's coverage of the Hasbro employee data breach explored the same long-tail problem. Identity and employment records can support impersonation long after a technical incident is closed.

The action to take today

The Times Car data breach is fresh, and the investigation is still developing. The safest response is specific and proportionate.

If you used or applied for Times Car, verify your status through the official site, secure reused credentials, review email and mobile recovery settings, monitor linked accounts, and distrust unsolicited breach-themed contact. If your individual notice confirms that identity documents were involved, use the strongest fraud and credit protections available where you live.

Businesses should warn enrolled employees, strengthen support verification, and watch for department-specific impersonation. Mobility platforms should review whether they retain identity documents, former-member records, and abandoned applications longer than necessary.

The absence of exposed card data is good news. It does not make this a minor breach. Payment cards can be replaced. A detailed identity profile is harder to contain, which is why the work now must focus on verification, recovery security, fraud monitoring, and data deletion that should have happened before an attacker arrived.