The confirmed breach affecting approximately 6.6 million Times Car accounts in Japan is significant not simply because of its size, but because of the sensitivity and long-term usefulness of the information exposed. Times Car says unauthorized access to its web systems resulted in the theft of customer information belonging to current members, former members, people who applied but did not complete enrollment, and current and former corporate-account users. The compromised information can include names, company department names, home addresses, dates of birth, phone numbers, email addresses, driver’s-license information, images of identity-verification documents, password representations, and linked-service identifiers. Credit-card information was not affected.
The company detected unauthorized access to its web system at 9:07 a.m. on September 25, 2026 and began investigating with external specialists. By 7:25 a.m. on September 26, Times Car says it had blocked the unauthorized access route, cut communications with the attack source, and verified that the attacker could no longer use the identified access path. The investigation subsequently confirmed that a third party had acquired customer information stored in the affected system. Times Car says it has not observed additional unauthorized access since containment, although forensic work remains ongoing.
The data categories involved make this incident particularly relevant for phishing, identity fraud, and impersonation. A database containing a customer’s name, address, date of birth, phone number, email address, and driver’s-license details gives an attacker enough verified personal context to produce highly credible social-engineering messages. If identity-document images were also exposed for a particular user, the value of the dataset increases further because scanned identity documents can sometimes be abused in fraudulent verification attempts or combined with other stolen information to defeat weak identity-checking processes.
Times Car has appropriately warned customers to be cautious about emails, SMS messages, and phone calls claiming to come from the company. That warning is especially important because the stolen information could make malicious communications unusually convincing. A phishing message that includes a person’s real name, membership details, address, or other accurate information immediately appears more credible than generic spam. Attackers could claim there is a problem with a reservation, membership account, billing issue, license verification, or security incident and then request credentials, authentication codes, or payment information.
The breach therefore creates a secondary risk that may persist long after the original intrusion is contained. Stolen personal data does not expire when the attacker loses access to the server. Email addresses, phone numbers, dates of birth, historical addresses, and identity-document details may remain useful for years and can later be merged with information from unrelated breaches to build increasingly detailed identity profiles.
The password exposure requires careful interpretation. Times Car says passwords were stored in a form that cannot be restored, and that the leaked information does not place passwords themselves in a state where they can currently be recognized by a third party. This wording strongly suggests a one-way password representation such as a hash, although Times Car has not publicly disclosed the precise algorithm, work factor, use of salts, or other password-storage details.
That technical detail matters. A properly salted password hash using a modern password-hashing algorithm such as Argon2, bcrypt, or scrypt presents a very different risk from an unsalted or computationally weak legacy hash. Saying only that a password is stored in a “non-restorable” form is reassuring to a point, but security teams evaluating the real credential risk would benefit from knowing the hashing method and whether unique salts and an appropriate work factor were used.
Even where password storage is strong, users who reused the same password on other services should remain cautious. If the underlying password hashes are ever cracked through offline guessing, reused credentials could be tested against unrelated email, shopping, financial, or cloud accounts. Password reuse has an unpleasant habit of converting one company’s security incident into several companies’ problem, because apparently humanity decided remembering unique passwords was one inconvenience too many.
Times Car says it has not confirmed that the stolen information has been made publicly available or that the incident has led to fraudulent misuse of customers’ personal information. That is an important distinction. Confirmed theft does not automatically establish public leakage or downstream abuse. However, the absence of currently observed misuse should not be interpreted as proof that the data will never be exploited. Threat actors may keep stolen datasets private, sell them selectively, combine them with other information, or use them months later.
The company also confirmed that credit-card data was not exposed, which substantially limits direct payment-card risk. That does not eliminate financial fraud concerns, because attackers can still use the stolen identity and contact information to conduct phishing designed to obtain card numbers, banking credentials, or authentication codes directly from victims. Indeed, customers may now be more susceptible to exactly that kind of fraud because attackers can reference authentic Times Car information while asking the victim to “reconfirm” payment information.
The inclusion of driver’s-license data is one of the more serious aspects of the incident. Driver’s licenses are widely used as identity-verification documents, and some affected users may also have had images of those documents stored in the compromised environment. Unlike passwords, identity-document numbers and personal biographical details cannot always be changed easily after a breach. This makes protection against secondary identity fraud particularly important.
Organizations handling identity-document images should therefore treat them as high-value data and minimize both their retention time and accessibility. If identity documents are required only during onboarding, companies should evaluate whether retaining complete images indefinitely is actually necessary. Data that no longer serves a legitimate business or regulatory purpose cannot be stolen if it is no longer stored.
The affected population also includes former Times Car members and people whose membership applications were never completed. That is a useful reminder about data-retention risk. Former customers naturally have far less ability to understand why their data remains stored years after they stop using a service. Retaining historical customer information may satisfy legitimate legal or operational requirements, but every retained record expands the eventual breach impact.
Data-retention policies should therefore be based on necessity rather than convenience. Organizations should know what customer information they retain, why they retain it, how long each category is required, and when it should be securely deleted or anonymized. A database containing millions of former users becomes a security liability if those records no longer provide corresponding business value.
The corporate-account impact also warrants attention. Times Car says affected accounts include current and former users of the Times Business Service corporate-account program, and department names may be among the leaked information. This gives attackers additional context for business-focused phishing. An attacker who knows both a user’s corporate affiliation and Times Car membership could impersonate either Times Car or the employer’s travel, procurement, finance, or administration team.
For example, criminals could send messages claiming that a corporate mobility account requires reactivation or that a company administrator must confirm billing details following the breach. Such targeted messages may be more effective than ordinary consumer phishing because they exploit both personal and workplace context.
The linked-service identifiers are another category that deserves review. Times Car says nine linked-service identifiers were affected, including identifiers associated with services such as JR West’s WESTER ID. A service identifier alone does not necessarily allow access to another account, but linked identifiers help attackers map relationships between user identities across different digital platforms. That information can improve account-enumeration, credential-stuffing, or social-engineering attempts.
The forensic investigation now needs to establish the initial access vector. Times Car has confirmed unauthorized access and data theft but has not yet publicly disclosed whether the intrusion involved exploitation of a software vulnerability, compromised credentials, an exposed administrative interface, a supply-chain issue, or another route. That technical root cause will determine the most important lessons for preventing recurrence.
The company says it is working with an external forensic organization, has reported the matter to Japan’s Personal Information Protection Commission and police, and plans to publish additional findings and longer-term preventive measures. That next disclosure will be important because breach response should ultimately explain not only what data was lost, but why the control failure occurred and what architectural changes will prevent it happening again.
For incident responders, the investigation should reconstruct the attack timeline from the earliest evidence of compromise rather than beginning only with the September 25 detection. Authentication logs, web-server access logs, database logs, privileged-account activity, API calls, firewall telemetry, endpoint events, and outbound network connections should be correlated to determine when access first occurred and whether the attacker established persistence or accessed additional systems.
The distinction between detection time and compromise time is crucial. An organization may discover an intrusion on one date even though attackers have been present much longer. Only forensic analysis can establish the actual dwell time.
Investigators should also determine whether the attacker merely queried customer records through the application layer or gained broader access to application servers, databases, identity infrastructure, or administrative systems. If privileged systems were compromised, remediation may require credential rotation, certificate replacement, service-account review, and rebuilding affected infrastructure rather than merely closing the original access route.
Because customer identity information was stolen, Times Car should also closely monitor for account-recovery abuse. Attackers possessing real identity details may attempt to impersonate customers through support channels, especially where customer-service verification relies on knowledge-based questions involving addresses, phone numbers, dates of birth, or membership details.
This is one reason knowledge-based authentication becomes steadily weaker after large breaches. A question such as “What is your date of birth?” stops functioning as meaningful authentication once millions of records containing dates of birth circulate among criminals.
Users affected by the incident should be especially suspicious of messages creating urgency around the breach itself. Attackers routinely exploit breach notifications by sending fraudulent “security verification,” “compensation,” “password reset,” or “account protection” messages. Times Car explicitly says it will not ask customers by email, SMS, or phone to provide passwords or credit-card details.
Customers should therefore navigate directly to Times Car through known official channels rather than following links in unsolicited breach-related messages. Any reused password should be changed on other services, and suspicious authentication or account-recovery activity should be treated seriously.
The scale of the Times Car platform helps explain the impact. The company operates a major nationwide car-sharing service across Japan. BleepingComputer reports that Times Car had approximately four million active members as of August 2026, with around 84,000 vehicles across 29,000 stations spanning all 47 Japanese prefectures. The affected count is larger than the current active membership because historical and incomplete membership records were also involved.
This incident therefore demonstrates another uncomfortable truth about data breaches: the eventual breach population may be significantly larger than the current customer population when organizations retain historical records.
The broader cybersecurity lesson is that identity-rich mobility platforms are attractive targets because they combine information from both the digital and physical worlds. A car-sharing provider may collect contact information, addresses, identity documents, driver’s-license details, corporate affiliations, and account credentials in order to establish that somebody is legally and operationally eligible to use a vehicle.
That makes the database valuable far beyond the immediate service.
An attacker obtaining that information does not necessarily need to attack the car-sharing platform again. The stolen data can instead become raw material for attacks against the users themselves.
The likely risk chain is:
web-system compromise → customer database accessed → identity and contact information stolen → attackers correlate data with other sources → targeted phishing or identity fraud → credentials or financial information stolen in follow-on attacks
The first breach belongs to Times Car.
The second attack may happen somewhere completely different.
That is why breach response should not end when unauthorized server access has been blocked. Customers need clear information about what fields were exposed, what those fields can realistically be used for, and which forms of follow-on fraud they should expect.
For Times Car, the next important disclosure should provide the technical root cause, the actual period of unauthorized access, the password-storage mechanism, and the controls being introduced to prevent recurrence.
The company has already confirmed the part customers care about most: their information was taken.
The remaining task is to establish how the attacker reached it, how long the access lasted, and whether any other systems or credentials were touched along the way.
Japanese car-sharing service Times Car has confirmed that approximately 6.6 million user accounts were compromised in a cyberattack disclosed late last week. [...]
Source: Times Car confirms data breach affecting 6.6 million user accounts via Bleeping Computer — published 28 Sep 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.