The news
Two major Japanese consumer brands disclosed cyber incidents in late September 2026. Park24 said about 6.6 million accounts were affected in the Times Car data breach at its car-sharing service, and rail and hotel group Keio confirmed a ransomware attack that disrupted some business systems, though it has not confirmed any information leak.
Park24 (TYO: 4666) said it detected unauthorized access to the Times Car web system on the morning of September 25 and finished blocking the intrusion route on the morning of September 26. In a September 28 update, it said about 6.6 million accounts were affected, covering current and former Times Car members, applicants who did not finish enrolling, and current and former members of its Times Business Service corporate program.
According to Park24, the information involved includes names, addresses, dates of birth, phone numbers, email addresses, driver's license information and identity verification document information, along with passwords and IDs for linked services. The company said credit card information was not leaked and that passwords were stored in a form that cannot be restored. It has engaged outside forensic specialists and reported the incident to Japan's Personal Information Protection Commission and to police.
Keio Corporation (TYO: 9008), whose businesses span trains, buses, real estate, hotels and retail, said it confirmed a ransomware attack on group servers in the early hours of September 26. The company said part of its group companies' business systems were disrupted but railway operations were not affected, and that no information leak had been confirmed. It reported the attack to police and brought in outside experts.
BleepingComputer reported that the incident appeared to affect Keio's hospitality business rather than train operations and, citing local media, that payment systems were disrupted. It said a notice on the Keio Plaza Hotel Tokyo website warned of possible delays to some customer-facing services, and it found no ransomware group claiming the attack as of September 28.
The incidents follow a record half-year for ransomware in Japan. The National Police Agency counted 123 ransomware cases from January to June 2026, the most for any six-month period since comparable statistics began, Telecompaper reported. Kyodo News, as published by Japan Today, reported that virtual private network (VPN) equipment was the most common infection route.
The numbers
- Times Car accounts affected (Park24)
- About 6.6 million
- Times Car intrusion detected / blocked (Park24)
- September 25 / September 26, 2026
- Keio ransomware attack confirmed (Keio)
- Early hours of September 26, 2026
- Ransomware cases in Japan, January-June 2026 (NPA, via Telecompaper)
- 123, a half-year record
Why CEOs should care
For companies with Japanese operations, customers or partners, the Times Car case is a reminder that identity data travels. Park24 said IDs for linked services were among the information involved, so partners that connect accounts to Times Car should check which of their identifiers sit in its systems. More broadly, ask each Japanese partner what customer data it stores for you, how quickly its contract obliges it to tell you about an incident, and whether that notice comes before or after its report to the Personal Information Protection Commission.
For CISOs, the national data points to basics. If VPN equipment was the most common ransomware entry route in the first half, as Kyodo reported, then VPN and remote-access appliances at Japanese subsidiaries belong on the same patch and monitoring schedule as headquarters systems. Keio's account, where group business systems were hit but trains kept running, is a useful test: could your hotel, retail or back-office networks fail without taking core operations with them?
For customer-facing teams and boards, the next wave after a breach is often fraud. Park24 warned members about emails, calls and texts impersonating the company and said it will never ask for passwords or card numbers that way. Companies whose customers overlap with affected services should prepare similar warnings and staff support lines.
The bigger picture
The Times Car case shows what is at stake when a consumer service keeps identity documents: Park24 listed driver's license information and identity verification document information alongside names, addresses and contact details among the data involved. That combination is more useful to fraudsters than a password alone. Diversified groups like Keio, which run rail, hotels and retail under one roof, also carry many separate systems that each need protection. The record NPA count suggests attackers are finding enough weak points to keep that pressure on.
What’s next
Park24's forensic review should show how the attacker got in and whether the intrusion began before September 25. Keio is still investigating whether customer or partner data was taken; a listing on a ransomware group's leak site would change that picture. Watch also for guidance from the Personal Information Protection Commission and for the police agency's full-year figures.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error









