Park24’s Times Car says breach exposed data on up to 6.6 million accounts
The Japanese car-sharing service says attackers took names, addresses, driver’s licence details and ID images, but not payment cards.
By Tech CEO Daily Staff, Newsroom
· 2 min read

The news
Park24, the Tokyo-based parking and mobility group, said on September 28 that unauthorised access to the web system behind its Times Car car-sharing service exposed personal information tied to approximately 6.6 million accounts. The company first disclosed a possible leak on September 25.
According to Park24’s second report, suspicious access was detected at 9:07 a.m. on September 25 and the intrusion route was cut off at 7:25 a.m. the next day. The affected records cover current and former members, people who began but did not finish sign-up, and users of the Times Mobility business service.
The exposed data includes names, addresses, dates of birth, phone numbers, email addresses, driver’s licence details, images of licences and other identity documents, department names for corporate members, and IDs for linked services such as JR West’s WESTER ID. Park24 said passwords were stored in a non-recoverable form and that credit card data was not affected. BleepingComputer reported the company saw no evidence the data had been distributed online.
Park24 said it has reported the incident to Japan’s Personal Information Protection Commission and to police, is notifying affected individuals, and will publish prevention measures after an external forensic investigation.
The numbers
- Accounts affected
- ~6.6 million
- Detected
- Sept 25, 2026, 9:07 a.m. JST
- Access blocked
- Sept 26, 2026, 7:25 a.m. JST
Why CEOs should care
Images of driver’s licences and ID documents are among the most damaging data to lose because they cannot be reset like a password and fuel identity fraud. Any business that collects identity documents for onboarding should ask: how long do we keep the images after verification, are they stored separately from the main customer database, and do we still hold data on former users and abandoned sign-ups? Park24’s exposure included both groups.
Corporate customers of mobility and travel services should also check whether employee data was shared through business accounts and whether linked-service IDs could expose other platforms.
The bigger picture
Japan has seen a run of cyber incidents at consumer-facing companies this month, including a ransomware attack on the Keio railway group’s hotel and retail systems.
Sources
Newsroom
Reporting and analysis from the Tech CEO Daily newsroom. Each story is researched from primary sources — company announcements, regulatory filings and official advisories — and fact-checked before publication.
Spotted an error? Request a correction. Read our editorial standards and AI policy.
The Daily Brief
The technology briefing for people running businesses.
Weekdays at 6 a.m. ET. Free.


