TIMES CAR BREACH EXPOSES 6.6 MILLION ACCOUNTS, INCLUDING 1.6 MILLION IDENTITY DOCUMENTS

COMPANY CONFIRMS LARGE-SCALE DATA THEFT

Times Mobility has confirmed that an attacker stole personal information associated with approximately 6.6 million current, former and prospective Times Car accounts.

In a September 29, 2026 update, the Japanese car-sharing operator disclosed that roughly 1.6 million affected accounts included copies of identity documents. The exposed files may contain driver’s-license images, proof-of-address documents, student IDs and documents used to verify family-plan eligibility.

The confirmation substantially raises the incident’s severity. Identity-document images can support convincing impersonation, fraudulent account creation and targeted social engineering long after passwords have been changed.

WHAT INFORMATION WAS STOLEN

The company detected unauthorized access to its web system at 9:07 a.m. on September 25. Its investigation subsequently confirmed that a third party obtained customer records stored in the compromised environment.

Depending on the account, the stolen information includes:

  • Names, addresses and dates of birth
  • Telephone numbers and email addresses
  • Driver’s-license information
  • Driver’s-license and other identity-document images
  • Corporate customers’ department names
  • Password representations
  • Identifiers connected to nine outside services, including WESTER ID

The affected population includes active and former Times Car customers, people who applied but did not complete enrollment, and current or former Times Business Service users.

Times Mobility says payment-card information was not exposed. It also says passwords were stored in a non-reversible format and that it has not confirmed public disclosure or misuse of the stolen information. Those assurances do not eliminate the phishing and identity-fraud risks created by the other exposed data.

ATTACK ACCESS HAS BEEN BLOCKED

Times Mobility says it completed blocking the intrusion path and communications with the attack infrastructure by 7:25 a.m. on September 26. Continued monitoring had not identified additional unauthorized access when the company published its second incident report.

The company is conducting a forensic investigation with outside specialists and has reported the incident to Japan’s Personal Information Protection Commission and police. Services remain operational.

Times Mobility has not publicly identified the initial-access method, a vulnerability, the attacker or the duration of access before detection. Any attribution or technical explanation circulating without additional evidence should therefore be treated as unverified.

WHY THE IDENTITY DOCUMENTS MATTER

The theft of approximately 1.6 million identity-document sets is the most consequential element of the breach.

A driver’s-license image can combine a verified photograph with a legal name, address, birth date and document identifiers. When paired with telephone and email data from the same breach, that information can make fraudulent identity checks and impersonation attempts considerably more persuasive.

The records could also be used to create highly tailored messages that reference a victim’s Times Car membership or appear to concern license verification, account suspension or compensation. Because former customers and incomplete applicants are included, people who no longer consider themselves Times Car users may still be affected.

WHAT AFFECTED CUSTOMERS SHOULD DO

Times Mobility began emailing people whose identity documents were confirmed stolen on September 29. Customers should verify notices independently through the official Times Car website rather than following links in unsolicited messages.

Affected individuals should:

  • Treat unexpected Times Car emails, calls and text messages as potentially malicious.
  • Never disclose passwords, payment details or one-time authentication codes in response to an inbound contact.
  • Change any password reused on another service, even though Times Mobility says the exposed password values were non-reversible.
  • Monitor financial, mobile and online accounts for unfamiliar activity.
  • Preserve the company’s notification in case proof of exposure is required for a fraud report.
  • Consider protections available in their jurisdiction against fraudulent credit or account applications.

Organizations whose employees used corporate Times accounts should brief help desks and security teams about likely impersonation attempts. Detection teams should watch for messages using the breach as a pretext to capture credentials or multifactor-authentication codes.

Leave a Comment

Your email address will not be published. Required fields are marked *