Park24, the parking and mobility group that owns Japanese car-sharing service Times Car, has confirmed that an unidentified third party took member data covering about 6.6 million accounts from the Times Car web system. Park24's second notice, published September 28, 2026, says the stolen data includes names, addresses, dates of birth, contact details, driver's license information and images of identity documents such as driver's licenses. Every source reviewed gives the same account count of roughly 6.6 million, and every source agrees that no credit card data was taken. No threat actor has claimed the attack. Park24 has not described how the attacker got in.
What Happened
Park24's own notice gives the timeline. The company detected unauthorized external access to the Times Car web system at 9:07 a.m. JST on September 25. It began investigating right away and brought in outside specialists. By 7:25 a.m. on September 26 it had cut off the access route, blocked communication with the attack source, and checked that the route could no longer be used. The Japanese outlet Act calculates that containment took about 22 hours from detection. Park24 says it is still monitoring and has seen no new unauthorized access.
The disclosure came in two stages. The first notice, issued on September 25 by operator Times Mobility, described only a possible leak. The second notice, on September 28, confirmed that a third party had taken part of the member data stored on the compromised system. JR West posted its own advisory on September 25 because its WESTER ID is one of the linked services involved.
Accounts of when the intrusion began differ. BleepingComputer reports that a third party accessed Times Car's systems "at the beginning of the month." Park24's notice gives only the detection time of September 25 and does not say when the attacker first got in. Until the forensic report is out, the intruder's dwell time should be treated as unknown. It may be much longer than the 22-hour detection-to-block window. An ok.com write-up dates all of these events to March 2026. Those dates conflict with every other source, including Park24's own notice, and look like an error.
Park24 says it has reported the incident to Japan's Personal Information Protection Commission and to the police. It will contact affected people individually and publish prevention measures in a later update. Service has not been disrupted. Act, citing media reports, says Park24's share price fell on the Tokyo market on September 28.
What Was Taken
Park24 puts the number of affected accounts at about 6.6 million. BleepingComputer, BigGo, Act, Oricon/Yahoo! News and Fukushima Minpo all repeat that figure without variation. The affected people are:
- Current and former Times Car members, including applicants who never finished signing up
- Current and former members of Times Business Service, the corporate account program
The data exposed differs from person to person, but Park24 lists these categories:
- Full name
- Department name (corporate members)
- Physical address
- Date of birth
- Telephone number
- Email address
- Driver's license information
- Identity verification document information, including driver's license images
- Account password
- Linked service IDs, from 9 partner services including JR West's WESTER ID
Park24 says passwords were stored "in a form that cannot be restored" and that they cannot be used to take over accounts. BleepingComputer reads this as meaning the passwords were hashed or encrypted. The company has not named the algorithm or said whether salting was used, so it is not yet possible to judge how well the passwords would hold up against offline cracking.
JR West says its own systems were not breached and that WESTER passwords are managed by JR West, so they were not exposed. It still advises users who reused the same password elsewhere to change it.
Park24 has confirmed that credit card data was not taken. It says it has no evidence that the data has been published or misused.
The 6.6 million figure is well above the 4 million active members Times Car reported as of August 2026, according to BleepingComputer. The gap suggests that a large share of the affected people are former members or unfinished applicants whose records, including identity documents, were still being kept.
Why It Matters
Identity documents cannot be changed the way passwords can. A password can be reset. A name, date of birth, address and driver's license image cannot. Together, these are enough to try to pass remote identity checks used by other services, such as account opening, SIM registration or other car-sharing platforms. Act says this is the most serious aspect of the breach, and defenders should expect the data to be useful to fraudsters for years.
Keeping data too long made the breach bigger. The affected group includes people who left the service and people who never completed registration. Their license images were still on the system. Act puts it simply: data you no longer hold cannot leak.
Corporate accounts give attackers material for targeted phishing. Leaked department names for Times Business Service members make convincing messages to corporate staff easy to write, for example fake invoices, booking confirmations or account alerts that include real names and departments.
Linked-service IDs extend the risk to partners. Nine partner services had user IDs exposed. Their own systems were not breached, but attackers can pair the IDs with the stolen personal data to make phishing that appears to come from those partners. This is why JR West put out its own warning.
The Attack Technique
The attack technique has not been disclosed. Park24 has not said which vulnerability, credential or entry point was used. It has not named a threat actor, and no group has publicly claimed the attack. Ok.com says the company has not stated whether it received a ransom demand. Park24 says an external forensic investigation is still working out the cause and full scope.
What the sources do establish:
- The target was the internet-facing Times Car web system, and the attack came from outside.
- The attacker had access to a data store holding identity document images as well as profile data. This suggests access to back-end storage, not only to the front-end application.
- Containment required cutting off an "access route" and ending communication with the attack source. This fits a persistent channel or an active exfiltration session, but that is our inference, not something Park24 has confirmed.
It is still unclear whether the intrusion started early in September, as BleepingComputer reports, or close to the September 25 detection. The answer matters, because a longer dwell time would point to a gap in detection as well as the initial compromise.
What Organizations Should Do
- Set retention limits for identity documents and enforce them. Delete license and ID images once verification is done, or when an account closes or an application is abandoned. If you must keep something, keep a verification result or a token, not the image.
- Store verification documents separately from the main application. Keep ID images in their own segmented storage with separate credentials, short-lived access tokens and alerts on bulk reads, so a compromised web tier cannot reach the whole archive.
- Watch for bulk exfiltration from customer data stores. Alert on unusual query volumes, large object-storage downloads and long outbound sessions from web systems. A 22-hour gap between detection and blocking is a long time for data to keep leaving.
- Harden password storage and say publicly how you do it. Use a modern, salted, memory-hard algorithm such as Argon2id, scrypt or bcrypt, and name it in breach notices so users and partners can judge the risk.
- Prepare for impersonation attempts using this data. Organizations with Times Business Service accounts should warn staff about fake Times Car or partner messages that cite real departments. Services that verify identity remotely should add liveness checks or other factors, rather than relying only on a license image.
- Plan partner notification ahead of time. When linked IDs are exposed, partners need early notice and a shared message, as JR West did on the day of Park24's first notice.
Sources: Times Car confirms data breach affecting 6.6 million user accounts | Park24's Times Car Suffers Data Breach Affecting 6.6 Million Record... | タイムズカーに不正アクセス 会員情報約660万件が流出、免許証画像も - 株式会社アクト | Park24 Times Car Breach: 6.6M Records, License Images Leaked - ok.com | タイムズカーWebシステムへの不正アクセスに関する調査結果および今後の対応について(第2報)|パーク24株式会社 | 「タイムズカー」Webシステムで660万件の情報漏えいを発表 会員、退会済み者も「深くお詫び申し上げます」(オリコン) - Yahoo... | タイムズカーWebサイトへの不正アクセスについて WESTER ポータル | タイムズカーで個人情報漏えい 福島民報デジタル