// 1 ZERO-DAY · 5 CVE · 4 EXPLOIT IN THE LAST 24H→
Times Car confirms a data breach compromising approximately 6.6 million accounts with names, addresses, and driver's license images. Unauthorized access was detected on September 25, 2026, and blocked the following day, with data theft confirmed on September 28.

Times Car, a Japanese car-sharing service operated by the Park24 Group, has confirmed the theft of personal data belonging to approximately 6.6 million current and former member accounts. Unauthorized access to the web system was detected at 9:07 a.m. on September 25, 2026, and blocked at 7:25 a.m. the following day. Confirmation of actual data exfiltration arrived on September 28, 2026, closing a phased disclosure window that left users uncertain for 72 hours about whether their data had been extracted or merely accessible.

Key Takeaways
  • Approximately 6.6 million current and former Times Car member accounts were compromised, including users of the corporate Times Business Service program.
  • Exposed data includes names, addresses, dates of birth, phone numbers, email addresses, driver's license information and images, passwords stored in a reportedly non-recoverable form, and linked service IDs.
  • Unauthorized access was detected on September 25, 2026 at 9:07 a.m. and blocked on September 26, 2026 at 7:25 a.m., with communications to the attack source severed.
  • Credit card data was not compromised, and Times Car services remained operational with no impact on availability.

Technical Profile: 22 Hours of Access and Documentary Identity Data

The technical timeline provided by Park24 via BigGo Finance is precise to the minute: detection at 9:07 a.m. on September 25, containment completed at 7:25 a.m. on September 26. This amounts to a roughly 22-hour window during which the attacker maintained access to the Times Car web system. The sources do not reveal the initial access vector: no exploited vulnerability is described, nor any reference to stolen credentials or specific social engineering techniques.

What distinguishes this incident from a conventional data breach is the nature of the exposed data. Beyond standard personal identifiers — name, address, date of birth, phone, email — the source documents the exfiltration of "driver's license information and document images." In a car-sharing service, license collection is a non-negotiable regulatory requirement; users cannot opt out. The result is a concentration of biometric-documentary data that, when compromised, amplifies impact far beyond simple contact-data exposure.

"The inclusion of driver's license images is particularly concerning as it heightens the risk of identity fraud and secondary damage"

Passwords, according to Times Car's statement reported by daily.dev, were "stored in a non-recoverable form." The phrasing is vague: it implies hashing or encryption but does not specify the algorithm or the presence of salting. The source does not allow determination of whether the corporate claim is technically verifiable or a convenient formulation.

Architectural Separation That Contained the Damage

One technical fact emerges clearly from both primary sources: credit card data was not compromised. Daily.dev states explicitly that "credit card data was not affected"; BigGo Finance confirms that "no credit card information was leaked." This separation suggests architectural isolation between the compromised web system and the payment infrastructure, likely based on tokenization or a separate processing environment.

All Times Car services remained operational during and after the incident. According to BigGo Finance, "no impact on Times Car service availability has been confirmed." This indicates the attacker did not deploy destructive or service-blocking techniques — ransomware, wipers, or denial of service — but focused on silent data exfiltration. The absence of availability impact likely delayed perception of the event's severity, contributing to the stepped disclosure timeline: detection, containment, theft confirmation.

The Regulatory Paradox: When Legal Requirements Become Attack Surface

The analytical angle suggested by the brief — and supported by available data — concerns the structural paradox of mobility services. A driver's license is a government-issued identity document that, once compromised in image form, cannot be "rotated" or replaced with the same ease as a password. Users cannot revoke their license or generate a new version. The document image becomes permanent data in the attacker's hands, usable for identity fraud, document forgery, or as a verification element in document-based second-factor authentication.

This creates a policy problem that transcends any single company. Car-sharing — and mobility-as-a-service more broadly — are legally required to verify user identity and driving eligibility. Technical alternatives exist: one-time verification with image destruction after validation, identity tokenization with service credential issuance, storage of only cryptographic hashes of document data. None of these options are documented as adopted by Times Car in the available sources.

Attribution and Context: No Link to ShinyHunters

During the breach period, contextual sources document ShinyHunters activity against U.S. government recruitment portals. Help Net Security and the BBC report details on this campaign, while IC3.gov issued a public advisory. No source establishes a link between ShinyHunters and the Times Car incident. The dossier names no threat actor for this specific breach. Inserting the ShinyHunters name into the Times Car narrative would be an unsupported narrative stretch.

At present, no evidence indicates the stolen data has been published online. Daily.dev explicitly reports this condition. The absence of publication could indicate several dynamics: an attacker retaining data for future use, an undisclosed negotiation phase, or simply an illicit market not yet observed. The dossier documents no ransom demands or extortion attempts.

Why It Matters

The dossier does not specify the attack vector used for initial access, making it impossible to assess the incident's preventability. It is not documented whether access occurred via an unpatched vulnerability, compromised credentials, or another mechanism.

The exact protection applied to passwords — hashing, algorithm, presence of salting — is not detailed in the sources beyond the generic "non-recoverable form" claim. This gap prevents estimation of credential cracking risk.

The dossier does not document specific remedial measures adopted by Park24 beyond access blocking and initiation of a forensic investigation with external agencies. It does not emerge whether architectural changes, system credential rotations, or access policy reviews were implemented.

Park24 stated it is evaluating the impact on financial results and reserves the right to disclose material impacts. At publication, no quantitative estimate of direct or indirect costs is available in the sources.

The company advised members never to provide passwords or credit card data in response to emails, SMS, or phone calls. Park24 further specified it will never request such information through these channels. This is a communication measure against second-order phishing, not a technical mitigation of the incident.

Phased Disclosure and Crisis Communication

The disclosure sequence — detection, containment, theft confirmation over three days — illustrates a crisis communication model that prioritizes certainty over speed. Park24 waited for confirmation of actual exfiltration before characterizing the event as data theft, avoiding a "potential breach" notice that would have required retraction. This approach, however, left users without complete information for 72 hours in a market — Japan — particularly sensitive to personal data protection.

For the car-sharing and mobility-as-a-service sector, the incident serves as a case study on the tension between regulatory identity-verification requirements and data concentration risk. Mandatory collection of identity documents creates honeypots of highly sensitive information that, when compromised, exceed the impact of conventional contact-data breaches by orders of magnitude. The architectural separation that preserved payment data proves isolation is possible; its application to documentary data remains an unexplored area in the available sources.

FAQ

Was my driver's license data exposed?
If you were a Times Car member or part of the Times Business Service program, sources confirm that driver's license information and images are among the compromised data. The dossier does not specify whether exposure is total or partial relative to the entire user base.

Should I change my Times Car account password?
The dossier contains no specific operational recommendations on this point. Passwords were stored in a reportedly non-recoverable form, but the exact protection type is not documented.

Is there a risk my data will be published online?
According to daily.dev, no evidence of online publication of the stolen data has been detected. This condition is verified as of the theft confirmation date but does not guarantee against future publication.

Information has been verified against cited sources and is current as of publication.

Sources


Sources and references
  1. helpnetsecurity.com
  2. daily.dev
  3. finance.biggo.com
  4. ic3.gov
  5. bbc.com