Yaamlabs
Threat intel

Times Car breach: 6.6M accounts and licence images

Japan's Times Car lost data on 6.6 million accounts, including driver's licence images. What leaked, who is affected, and what members and firms should do.

By Yaali. September 29, 2026, 6 min read, Threat intel, Identity.

Cover illustration of a small car in a dark parking bay with two glowing ID cards drifting away from it, with the Yaamlabs logo and the text: Times Car breach leaks driver's licence images, 6.6M accounts, former members included

Park24, the Japanese parking and mobility group behind the Times Car car-sharing service, confirmed on September 28 that a third party obtained member data for about 6.6 million accounts. The attack was detected at 9:07 JST on September 25, the first notice went out the same day, and the company says it had cut the intruder's access path and communications by 7:25 JST on September 26.

The data includes driver's licence details and images of identity documents, alongside names, addresses, dates of birth, phone numbers and email addresses. The affected accounts cover current members, people who closed their accounts, people who started signing up and never finished, and current and former corporate users of Times Business Service. If you, your staff or your customers ever rented a Times Car in Japan, even once and years ago, assume the record is in the set until your notification says otherwise.

Stat tiles and field list for the Times Car breach: 6.6 million accounts, detected September 25 at 9:07 JST, blocked September 26 at 7:25 JST, nine linked service IDs, the exposed and not-exposed fields, and the groups of people whose records were taken

What was taken, and what was not

Records vary from person to person, but the confirmed fields are: name, address, date of birth, phone number, email address, driver's licence information, identity document images (driver's licences among them), the account password in a form Park24 describes as non-recoverable, and IDs for nine linked partner services. For corporate accounts, the user's department name is also in the set.

Credit card data was not taken. Park24 says it has seen no sign that the data has been published or misused so far, and it has reported the incident to Japan's Personal Information Protection Commission and to the police. It will notify affected people individually, in stages.

One of the nine linked IDs is WESTER ID, the membership account of the JR West railway group. JR West published its own notice saying WESTER passwords are managed in-house and were not exposed. The ID itself was taken, so an attacker can link a Times Car identity to a rail account but cannot log in to it from this data alone.

How it happened, as far as is known

Park24 has not said how the attacker got in. Its notices describe unauthorized access to the Times Car web system, confirmed third-party acquisition of member data stored in it, and an investigation by outside forensic specialists that is still running. We found no public claim by any group, and BleepingComputer reports no evidence so far that the data has leaked online. Some early English coverage said the access began in early September; the company's own notices give no start date, so treat that as unconfirmed.

What the notices do show is a retention problem. Former members and abandoned sign-ups sat in the same web-reachable system as active customers, with their licence images still attached. A car-sharing service has to check a licence before the first rental. It does not obviously need the picture of that licence years after someone closes their account, or at all for someone who never finished joining.

The password point needs care too. "Non-recoverable" means the passwords were hashed, a one-way transformation, rather than stored in plain or reversible form. That stops an attacker reading them straight out of the database. It does not stop offline guessing: an attacker with the hashes can try common and leaked passwords at high speed, and how many fall depends on the algorithm and salting, which Park24 has not disclosed. Park24 says there is no risk of unauthorized account use from this information. For anyone who reused the same password somewhere else, the safer assumption is that a weak one can be cracked.

Why licence images matter more than the rest

A name, address and phone number enable spam and phishing. An image of a real driver's licence goes further, because many services still verify identity by asking for a photo of an ID document. In Japan, that upload-a-picture method (known as "ho" under the Act on Prevention of Transfer of Criminal Proceeds) is still permitted for opening bank and other financial accounts, and it is scheduled to be largely abolished only on April 1, 2027, when online checks move to reading the IC chip in the card. The change was driven in part by fraud with forged ID documents that passed visual checks. Until then, a stolen licence image combined with matching address and birth date is useful raw material for impersonation.

Licence scans are also a proven target outside Japan. Earlier this month, IDScan.net, a US identity-verification firm whose customers include car rental businesses, confirmed a breach after a dark web platform advertised more than 153 million US and Canadian driver's licence scans. Any business that collects ID images holds the same kind of asset.

What to do

Four actions after the Times Car breach: members change reused passwords, members and staff expect targeted lures, firms with corporate accounts brief their users, and anyone who keeps ID scans deletes images once checked

If you are or were a member. Change the password on every other service where you used your Times Car password, starting with the email account on file. Then change it in Times Car. Times Car says it will not ask for passwords, authentication codes or card details by email, SMS or phone, so treat any message about a refund, a licence re-check or a suspended account as hostile and open the app yourself instead of following a link.

If your company used Times Business Service. Export the list of employees registered under your corporate account and tell them first, before a phishing message does. The leaked department names let an attacker write a convincing internal-looking lure or pose as a colleague. Tell your help desk that a caller who knows an employee's name, department, address and licence number has proved nothing: those are now in the stolen set. Resets of passwords and MFA (multi-factor authentication) for those staff should go through a callback to a number already on file.

If your business collects ID images. Keep the outcome of the check (verified, date, document type, last digits of the number) and delete the image once a person or system has confirmed it. Run a scheduled purge for closed accounts and abandoned sign-ups, and make sure it actually deletes from backups and object storage, not just the application table. Keep any images you must retain out of the web tier: store them in a separate service that the public-facing application can write to but not bulk-read, and alert on reads above a normal daily volume. If you operate in Japan and still accept photo-only ID checks, the April 2027 deadline is the natural point to move to IC chip verification and stop collecting images at all.

The wider lesson

The 6.6 million count includes people who had closed their accounts and people who never became customers. An attacker takes whatever the reachable system holds, so retention rules set the size of a breach long before anyone attacks. A data map that lists each personal-data field, why it is kept and when it is removed gives you something to test that against: pick a closed account from two years ago and check whether its ID image still exists anywhere.

If you want to know what an attacker would reach in your own customer portal, our web penetration testing finds that path, and our compliance and audit readiness work covers data retention and deletion. Open the chat and Yaali, our AI agent, will pass your question to the engineer who would do the work.


Sources: Park24 second report, Times Car first report, Times Car second report, WESTER portal notice, BleepingComputer, INTERNET Watch, piyolog, Nikkei, DNP on the 2027 eKYC change, TRUSTDOCK on the 2027 eKYC change, BleepingComputer on IDScan, Krebs on Security on IDScan.

Read next

Back to the blog, or tell us about your system in the chat. Yaali, our AI agent, answers first and brings in an engineer.