Times Car, Japan's largest car-sharing service, has confirmed that a breach discovered late last month compromised the personal data of as many as 6.6 million current and former members — one of the largest breaches reported in the country this year.
Park24 Group, which runs the service through subsidiary Times Mobility, said a third party gained unauthorized access to the Times Car reservation system around Sept. 1, that the intrusion was detected the morning of Sept. 25, and that the access was cut off by the following day. The company's account of the incident, and the scope of data exposed, was detailed by BleepingComputer, which reported the intruder had access to company systems for close to a month before detection.
The 6.6 million figure covers current and former individual Times Car members as well as users of its Times Business Service corporate account program — a striking scale for a company that reported roughly 4 million active members as of August. Not every outlet treats the number as final: trade publication MLex has reported that 6.6 million represents the maximum number of potentially affected accounts, with investigators still working to pin down the precise scope.
Exposed data includes members' names, addresses, birth dates, phone numbers, email addresses and driver's license details, Times Car said. Separately, identity-verification documents — including photos of driver's licenses, utility bills showing home addresses, and student IDs submitted for discounted plans — leaked from about 1.6 million accounts. The company said account passwords were stored in "a form that cannot be restored," language that implies encryption or hashing, though it did not elaborate further. Credit card information, it said, was not affected, and there is no evidence so far that the stolen data has surfaced for sale online.
Security researchers have flagged the leaked identity documents as the more serious long-term risk. Photographs of government-issued IDs and proof-of-address paperwork can be reused to pass identity checks at other services, a harder problem to remediate than a leaked password, which can simply be reset. Times Car is notifying affected members in stages, has reported the incident to Japan's Personal Information Protection Commission and police, and is urging members to be wary of phishing emails, texts and calls impersonating the company. Its services, including online reservations for roughly 84,000 vehicles across all 47 Japanese prefectures, remain operational throughout.
An external forensic investigation into how the intrusion occurred is ongoing, and Park24 has not yet said whether it has identified the attacker or the method used to breach its systems.