Times Car Rental says data breach affected 6.6 million accounts

The operator of Times Car Rental, a popular car-sharing service, has announced that a data breach last week led to the leak of information associated with 6.6 million accounts, including images of personal IDs — a particularly rare type of breach.
The firm, Times Mobility, first detected the breach last Friday morning and confirmed that an unauthorized third party had accessed the company’s data, before blocking the access route by the next morning.
It said that 1.6 million documents had been accessed, including pictures of documents that the company used to verify personal information, such as utility bills for home addresses and student IDs for those signing up for a student plan. Personal photos were confirmed to have been accessed through driver’s licenses.
The 6.6 million accounts breached in the hack were of both current and former Times Car and Times Business Service members. Personal account information included names, home addresses, telephone numbers, and email addresses. However, no credit card information was accessed.
“An external specialist is conducting a forensic investigation to determine the cause and scope of the incident,” parent company PARK24 said in a statement. “We are also taking the necessary steps, including reporting the incident to the Personal Information Protection Commission and the police.”
The leak of personal photos is unusual, according to data security experts, and is concerning because it could open up more malicious uses, including identity theft or the fraudulent use of services that require verification.
The Credit Information Center, a credit information agency, said Tuesday that due to high volume, it would be difficult for customers to immediately reverify their identities or to check loan and credit disclosures made in their name.
The Japan Credit Information Reference Center, another agency, also announced Wednesday that they were receiving a high volume of similar requests, leading to processing delays and errors on their smartphone app.
While Times Mobility announced that there has been no effect on its services’ operations, the firm has begun reaching out to users whose information was accessed. It also urged users to be wary of emails, phone calls and other messages impersonating the company, adding that it would never ask for passwords or credit card information through those means.
The number of unauthorized access cases has been on the rise in Japan. Over 7,190 incidents were recorded by the National Police Agency in 2025, a more than fourfold increase since 2021.
There have also been several high-profile incidents in recent months, including the breach of a government network that put the information of hundreds of thousands of employees at risk, and a cyberattack of frozen-foods logistics company Nichirei that affected restaurants, supermarkets and school lunch programs nationwide.
KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.