Skip to content
Tech CEO Daily

Park24’s Times Car says breach exposed data on up to 6.6 million accounts

The Japanese car-sharing service says attackers took names, addresses, driver’s licence details and ID images, but not payment cards.

TC

By Tech CEO Daily Staff, Newsroom

· 2 min read

A row of shared rental cars parked in a Tokyo parking lot at night under neon light
AI-generated image for illustration. Not a photograph of the events described.

The news

Park24, the Tokyo-based parking and mobility group, said on September 28 that unauthorised access to the web system behind its Times Car car-sharing service exposed personal information tied to approximately 6.6 million accounts. The company first disclosed a possible leak on September 25.

According to Park24’s second report, suspicious access was detected at 9:07 a.m. on September 25 and the intrusion route was cut off at 7:25 a.m. the next day. The affected records cover current and former members, people who began but did not finish sign-up, and users of the Times Mobility business service.

The exposed data includes names, addresses, dates of birth, phone numbers, email addresses, driver’s licence details, images of licences and other identity documents, department names for corporate members, and IDs for linked services such as JR West’s WESTER ID. Park24 said passwords were stored in a non-recoverable form and that credit card data was not affected. BleepingComputer reported the company saw no evidence the data had been distributed online.

Park24 said it has reported the incident to Japan’s Personal Information Protection Commission and to police, is notifying affected individuals, and will publish prevention measures after an external forensic investigation.

The numbers

Accounts affected
~6.6 million
Detected
Sept 25, 2026, 9:07 a.m. JST
Access blocked
Sept 26, 2026, 7:25 a.m. JST

Why CEOs should care

Images of driver’s licences and ID documents are among the most damaging data to lose because they cannot be reset like a password and fuel identity fraud. Any business that collects identity documents for onboarding should ask: how long do we keep the images after verification, are they stored separately from the main customer database, and do we still hold data on former users and abandoned sign-ups? Park24’s exposure included both groups.

Corporate customers of mobility and travel services should also check whether employee data was shared through business accounts and whether linked-service IDs could expose other platforms.

The bigger picture

Japan has seen a run of cyber incidents at consumer-facing companies this month, including a ransomware attack on the Keio railway group’s hotel and retail systems.

Sources

TC
Tech CEO Daily Staff

Newsroom

Reporting and analysis from the Tech CEO Daily newsroom. Each story is researched from primary sources — company announcements, regulatory filings and official advisories — and fact-checked before publication.

Spotted an error? Request a correction. Read our editorial standards and AI policy.

The Daily Brief

The technology briefing for people running businesses.

Weekdays at 6 a.m. ET. Free.

More in Cybersecurity