Park24's Times Car breach exposes data of 6.6 million car-sharing users (2026)
Japanese mobility group Park24 said unauthorized access to its Times Car car-sharing system exposed personal data, including driver's license images, for about 6.6 million members.
- Victim
- Park24 (Times Car)
- records
- 6.6M
On 25 September 2026, Tokyo-listed Park24 β a major Japanese parking and mobility-services company β disclosed that a third party had gained unauthorized access to the web system behind its Times Car car-sharing service, operated by its Times Mobility subsidiary. The company said the intrusion affected personal information tied to about 6.6 million current and former accounts, including members of its Times Business Service corporate program.
What happened
Park24 said the unauthorized access began earlier in the month and that it moved to block the intruder on 26 September. In a follow-up on 28 September, the company confirmed that data had been stolen. The exposed information included names, addresses, dates of birth, phone numbers, email addresses, driver's license details and images, account passwords, and linked service IDs. Park24 said the passwords were stored in an unrecoverable (hashed) form and that credit-card data was not affected. At the time of disclosure, there was no evidence the stolen data had been leaked online.
The company reported the incident to Japan's Personal Information Protection Commission, engaged an external expert for a forensic investigation into the cause and scope, and said it would notify affected customers in stages. It also said it was preparing measures to prevent a recurrence. Times Car services remained operational throughout, and the company urged members to stay alert for suspicious contact that could reference their leaked details.
Why it matters
Driver's license images and identity-verification documents are exactly the material needed to open accounts, pass "know your customer" checks, or commit identity fraud in a victim's name β making this breach more consequential than a simple email-and-password leak. The scale, 6.6 million accounts, also makes it one of the larger Japanese consumer data breaches disclosed in 2026, and a reminder that mobility and sharing-economy platforms now hold sensitive government-issued identity data at population scale.
Timeline
Park24 discloses unauthorized access to the Times Car web system, which it says began earlier in the month.
The company blocks the unauthorized access.
Park24 confirms data theft in an update, reporting the incident to Japan's Personal Information Protection Commission.
Sources
- bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/times-car-confirms-data-breach-affecting-66-million-user-accounts/
- mlex.comhttps://www.mlex.com/mlex/data-privacy-security/articles/2531097
- blog.rankiteo.comhttps://blog.rankiteo.com/paku1790584734-park24-breach-september-2026/