Skip to content
TECH CEO Daily

Times Car data breach affects 6.6 million accounts, Park24 says; Keio hit by ransomware

A car-sharing service holding driver's license data and a rail and hotel group both disclosed incidents as Japan logged a record half-year for ransomware.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Park24 said about 6.6 million Times Car accounts were affected, including driver's license and identity document information.
  • 2Keio confirmed a ransomware attack on group servers on September 26; trains ran normally and data theft was unconfirmed.
  • 3Japan's police counted a record 123 ransomware cases in the first half of 2026, Telecompaper reported.

The news

Two major Japanese consumer brands disclosed cyber incidents in late September 2026. Park24 said about 6.6 million accounts were affected in the Times Car data breach at its car-sharing service, and rail and hotel group Keio confirmed a ransomware attack that disrupted some business systems, though it has not confirmed any information leak.

Park24 (TYO: 4666) said it detected unauthorized access to the Times Car web system on the morning of September 25 and finished blocking the intrusion route on the morning of September 26. In a September 28 update, it said about 6.6 million accounts were affected, covering current and former Times Car members, applicants who did not finish enrolling, and current and former members of its Times Business Service corporate program.

According to Park24, the information involved includes names, addresses, dates of birth, phone numbers, email addresses, driver's license information and identity verification document information, along with passwords and IDs for linked services. The company said credit card information was not leaked and that passwords were stored in a form that cannot be restored. It has engaged outside forensic specialists and reported the incident to Japan's Personal Information Protection Commission and to police.

Keio Corporation (TYO: 9008), whose businesses span trains, buses, real estate, hotels and retail, said it confirmed a ransomware attack on group servers in the early hours of September 26. The company said part of its group companies' business systems were disrupted but railway operations were not affected, and that no information leak had been confirmed. It reported the attack to police and brought in outside experts.

BleepingComputer reported that the incident appeared to affect Keio's hospitality business rather than train operations and, citing local media, that payment systems were disrupted. It said a notice on the Keio Plaza Hotel Tokyo website warned of possible delays to some customer-facing services, and it found no ransomware group claiming the attack as of September 28.

The incidents follow a record half-year for ransomware in Japan. The National Police Agency counted 123 ransomware cases from January to June 2026, the most for any six-month period since comparable statistics began, Telecompaper reported. Kyodo News, as published by Japan Today, reported that virtual private network (VPN) equipment was the most common infection route.

The numbers

Times Car accounts affected (Park24)
About 6.6 million
Times Car intrusion detected / blocked (Park24)
September 25 / September 26, 2026
Keio ransomware attack confirmed (Keio)
Early hours of September 26, 2026
Ransomware cases in Japan, January-June 2026 (NPA, via Telecompaper)
123, a half-year record

Why CEOs should care

For companies with Japanese operations, customers or partners, the Times Car case is a reminder that identity data travels. Park24 said IDs for linked services were among the information involved, so partners that connect accounts to Times Car should check which of their identifiers sit in its systems. More broadly, ask each Japanese partner what customer data it stores for you, how quickly its contract obliges it to tell you about an incident, and whether that notice comes before or after its report to the Personal Information Protection Commission.

For CISOs, the national data points to basics. If VPN equipment was the most common ransomware entry route in the first half, as Kyodo reported, then VPN and remote-access appliances at Japanese subsidiaries belong on the same patch and monitoring schedule as headquarters systems. Keio's account, where group business systems were hit but trains kept running, is a useful test: could your hotel, retail or back-office networks fail without taking core operations with them?

For customer-facing teams and boards, the next wave after a breach is often fraud. Park24 warned members about emails, calls and texts impersonating the company and said it will never ask for passwords or card numbers that way. Companies whose customers overlap with affected services should prepare similar warnings and staff support lines.

The bigger picture

The Times Car case shows what is at stake when a consumer service keeps identity documents: Park24 listed driver's license information and identity verification document information alongside names, addresses and contact details among the data involved. That combination is more useful to fraudsters than a password alone. Diversified groups like Keio, which run rail, hotels and retail under one roof, also carry many separate systems that each need protection. The record NPA count suggests attackers are finding enough weak points to keep that pressure on.

What’s next

Park24's forensic review should show how the attacker got in and whether the intrusion began before September 25. Keio is still investigating whether customer or partner data was taken; a listing on a ransomware group's leak site would change that picture. Watch also for guidance from the Personal Information Protection Commission and for the police agency's full-year figures.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

Park24KeioJapanRansomwareData breach

Earlier coverage of Park24

All Park24 coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.