News / Cybersecurity
Cyberattack at Times Car: 6.6 Million Accounts Exposed in Japan Published on 28 September 2026 by Christ-loisele (2 min read)
The Japanese ridesharing service Times Car, a subsidiary of Park24, has confirmed a security breach affecting sensitive personal data of 6.6 million users. No evidence of leaked data has been found, but a thorough investigation is underway.
An intrusion detected at the start of September
Times Car, a Japan-based car-sharing platform, revealed on September 28, 2026, that a cyberattack allowed a third party to access its systems from the beginning of the month. The unauthorized access was blocked on September 26, according to the company’s statements. The incident affects 6.6 million accounts, including active members, former users, and subscribers to the Times Business Service , a program dedicated to businesses.
Passwords, stored in an irreversible format, could not be retrieved according to Times Car, partially mitigating the risk of impersonation.
Illustration: Lawing Tech
What types of data were compromised?
The exposed information includes full names, physical addresses, dates of birth, phone numbers, email addresses, driver’s license details, and images of identity documents used for verification. Passwords, stored in an irreversible format (likely encrypted or hashed), could not be retrieved, Times Car specifies. However, banking data, including credit card information, was not affected by the breach.
According to Bill Toulas and Mikko Hyppönen , cited by BleepingComputer , there is currently no evidence that the stolen data has been publicly leaked or misused.
Company response and ongoing investigations
Times Car, operated by Times Mobility (a subsidiary of the Park24 group, listed on the Tokyo Stock Exchange), states that its services are functioning normally despite the incident. The company has hired an external expert to conduct a forensic investigation, while reports have been submitted to Japan’s Personal Information Protection Commission and law enforcement authorities. Park24 issued a statement titled « Notice Regarding Unauthorized Access at a Consolidated Subsidiary's System and Personal Data Breach » , confirming the measures taken.
The data of Times Car’s 4 million active members, operating across 47 Japanese prefectures with 29,000 stations and 84,000 vehicles, remains potentially vulnerable despite the lack of evidence of a leak.
What this changes here
For Beninese or African businesses and administrations using shared mobility services or outsourced customer data management, this cyberattack underscores the importance of verifying the robustness of their technological partners’ security protocols. A similar vulnerability in a local system could expose sensitive information such as digitized identity documents, professional contact details, or service credentials, even though banking data typically remains isolated. Local stakeholders should strengthen their security audits and ensure that critical passwords are stored in an irreversible format, as recommended by the CERT-FR for exposed systems.
Moreover, the speed of detection and transparency demonstrated by Times Car could serve as a model for African platforms in crisis communication, particularly in a context where user trust is a key factor for the adoption of digital services.
Sources