Times Car, a car-sharing service owned by Japan's Times Mobility, has confirmed that a third party has obtained data on approximately 6.6 million accounts. The breach involved current and former members, as well as customers of its corporate program Times Business Service. The company says no credit card details were affected.

In its latest announcement, the company says it detected external access to its online system on September 25. With the assistance of external experts, it confirmed that a third party obtained some of the stored information. Access was reportedly blocked until the morning of September 26, while monitoring continues.
What data was exposed in the Times Car case?
The number of affected accounts is approximately 6.6 million. Users include active and former Times Car members, including people who started a registration but did not complete it, as well as current and former Times Business Service customers. The announcement therefore also concerns people who are not currently using the vehicles or who never completed their registration.
The list of data includes names, addresses, dates of birth, phone numbers, and email addresses. For corporate members, this may also include their work department. The data also includes driver's license information, images of licenses and other identification documents, passwords, and connected service identifiers.

The company said the leaked fields vary by person, so it should not be assumed that each account contained the entire combination. Among the nine linked service identifiers is the JR West group's WESTER ID. The statement did not attribute a specific group of perpetrators or describe the initial point of entry.
For the passwords, Times Car says they were stored in a form that cannot be restored and that, according to the company, they cannot be used for unauthorized access to the accounts. It has not been made public what protection technique was implemented. Therefore, it is not safe to assume that all passwords or other data are safe.
What Times Car knows about the consequences
The company confirms that credit card information is not included in the data removed. At the time of the September 28th announcement, it had not been determined that the data was publicly disclosed or misused. The statement refers to what was known at the time of the update, not a guarantee that the risk has been eliminated.
The investigation into the cause and extent of the breach is ongoing with the assistance of external experts. Times Car says it has notified the relevant authorities and the police, and will notify affected customers in a phased manner. In the meantime, the service continues to operate normally and new details will be made public in a subsequent update.
See also: Revolut: DriveWealth breach exposes personal customer data

How can members be protected?
Times Car warns of deceptive emails, SMS or phone calls pretending to be from the service. Compromised addresses, phones and identity information can make such attempts more convincing, even if they have not been reported to have been used.
Customers are urged not to open links or attachments from unexpected communications and not to enter passwords, verification codes or card details on pages opened by such messages. The company clarifies that it does not request such information via email, SMS or phone. For updates, users can type in the address of the official service themselves.
Anyone who used the same password on other services should change it there, choosing a different password for each account. Paying attention to notifications is also important for former members or those who did not complete their registration, since both groups are included in the affected groups.
The investigation into the data leak continues
The Times Car case stands out both for the number of accounts and the combination of contact details, identification documents and driving information. The fact that no publication or misuse of the data has been detected is positive, but the company has not yet completed its investigation.
Until more is announced about the cause and remediation measures, the SecNews editorial team points out that affected parties should treat any unexpected communication claiming a breach with caution. Particular caution is needed when personal information or actions are requested via a link.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Skroutz Last Mile: Access to shipment data without authorization
See also: How to recognize a fake profile on social media
