Skip to content

Times Car Rental Says Data Breach Affected 6.6 Million Accounts, Including Driver’s License Images, Park24 Confirms

Getting your Trinity Audio player ready...

Park24, the Tokyo-listed parent of Japan’s Times Car service, has confirmed that a data breach exposed information tied to about 6.6 million accounts, including images of driver’s licenses and other identity documents. The company disclosed the incident in two steps, first on September 25 with a warning that member data may have leaked, then on September 28 with a confirmation that a third party had viewed or taken the data. The case stands out because the stolen records go beyond contact details and reach into the identity documents that car-sharing services collect before they let anyone drive.

Times Car is run by Times Mobility, a Park24 Group company that also operates the Times Business Service program for corporate customers. The company says it detected unauthorized access to its web system at 9:07 a.m. on September 25 and cut off the attacker’s route by around 7:25 a.m. the next morning, according to details relayed from its notice. Reporting by The Japan Times says the firm described 1.6 million documents as accessed, including images used to verify personal information, and noted that no credit card information was involved.

The categories of exposed data vary from person to person, but the company’s list is long. It covers names, addresses, dates of birth, phone numbers and email addresses, along with driver’s license details, identity verification documents, account passwords and IDs from linked services. For corporate members, department names were also included. Park24 says passwords were stored in a form that cannot be restored to their original text, which lowers the immediate risk to those credentials, although it does not rule out attempts to guess weak ones.

The 6.6 million figure needs careful reading. It counts accounts, not individual customers. The total spans current and former Times Car members, people who started an application but never finished it, and current and former users of Times Business Service. Times Mobility announced in mid-August that Times Car membership had passed 4 million, so the breach figure is much larger than the active customer base. One analysis of the company’s own help pages notes that member information is kept for about seven years after someone leaves because of legal record-keeping duties. That would help explain why people who stopped using the service years ago, or who never completed sign-up, now find themselves among the affected.

Real More:  Anthropic, OpenAI, SpaceXAI and Google Face Antitrust Lawsuit Over Alleged AI Slowdown Collusion Under the Sherman Act

For the people involved, the risk depends heavily on what was taken. A driver’s license image is not like a leaked password. A password can be changed in minutes, but a license photo combined with a name, address and date of birth gives a fraudster much of what is needed to impersonate someone, open accounts, or pass weak identity checks. Security commentators have pointed out that the long-term danger lies in identity misuse rather than only phishing. The company has asked members to be careful with emails, text messages and phone calls that claim to come from Park24, and that is sensible advice, because attackers often use real names and addresses to make scam messages convincing.

Park24 says it has found no evidence so far that the stolen information has been published online or misused. Reports repeating the company’s statement also say credit card numbers were not leaked. Both points are the company’s own findings at an early stage, and they can change as the investigation proceeds. Park24 is working with an outside forensic specialist to determine the cause and the full scope, and it has reported the incident to Japan’s Personal Information Protection Commission and to the police. Times Car services continue to operate normally, and affected customers are being notified in stages.

Real More:  Tim Cook's Last Day as Apple CEO

The timeline raises one open question. Some security outlets, including BleepingComputer, have reported that the intruder may have had access to systems earlier in September, well before the September 25 detection. The company’s own notice anchors its timeline to the day it spotted the activity, so how long the attacker was inside, and what was copied during that time, is likely to be a central point of the forensic review. Readers should treat any claim about the start date as unconfirmed until Park24 publishes its findings.

The incident also arrived during a rough week for Japanese rental brands. Another operator, Nippon Rent-A-Car, announced on September 26 that a third party had gained unauthorized access to the system behind its mobile app and that member information may have been viewed. That company asked affected members to reset their passwords and also notified the data protection regulator and police. Nothing published so far links the two cases, and they involve different companies, so it would be wrong to treat them as one campaign. They do show how attractive mobility platforms have become as targets, since they sit on identity documents, payment relationships and location-linked accounts.

For anyone who has used Times Car, the practical steps are modest but worth taking. Watch for the company’s notification and read it carefully, since the details of what was exposed differ by account. Treat unexpected messages that mention Times Car, a license or a rental with suspicion, and avoid clicking links or returning calls from numbers in the message itself. If you reused your Times Car password on other sites, changing it elsewhere is a reasonable precaution even though the company says its stored copies are protected. People who submitted a license image may also want to keep an eye on credit reports and account activity where that is possible in their country, and to ask the company how long it will retain their documents going forward.

Real More:  Novo Nordisk Will Use Anthropic's Claude and Claude Science for Drug Research in a New AI Pharmaceutical R&D Partnership

The wider lesson for any business that verifies customers with identity documents is about retention. Collecting a license image to confirm someone’s eligibility to drive is routine, but keeping it for years after the relationship ends multiplies the damage when a breach occurs. Regulators in many countries ask companies to keep personal data only as long as it is needed, and incidents like this one tend to sharpen that debate. Companies that handle ID images can reduce exposure by storing them separately from account data, deleting them once verification is done where the law allows, and encrypting what remains.

What happens next is fairly clear. Park24 still owes its customers a full explanation of how the attackers got in, how long they stayed and which records were actually copied, and it has said it is preparing measures to prevent a repeat. Regulators in Japan will review the filing, and affected users will be waiting to learn whether any of the stolen material appears for sale or in scam campaigns. Until then, the 6.6 million figure is best read as the upper bound of accounts touched, not a count of confirmed victims of fraud.

Readers who follow how large breaches and identity-theft risks affect businesses and consumers across Africa can find more technology and security coverage at BusinessTech Nigeria.

Leave a Comment