Times Car (Park24 / Japan): ~6.6M member accounts — names, licence images, hashed passwords; cards said unaffected
Japanese car-sharing service Times Car (Times Mobility / Park24 Group) confirmed a cyberattack that compromised approximately 6.6 million current and former Times Car member accounts and Times Business Service corporate-program members. Company first announced unauthorised access beginning of September 2026 (public notice 25 Sep); blocked access 26 Sep; BleepingComputer (28 Sep) reports today’s update confirming data theft. Exposed data per company update: full name; corporate department; address; date of birth; phone; email; driver’s licence information; identity-verification document images (e.g. licence photos); account password (stored in a form that “cannot be restored” — hashed/encrypted, detail not expanded); linked service IDs. Credit card information stated unaffected; no evidence of online distribution at time of reporting. Services continue; staged individual notifications. Primary wire: BleepingComputer 28 Sep quoting company; seek Park24/Times Mobility primary notice when mirrored in English.
- Product
- Times Car / Times Mobility (Park24 Group) member systems
- Versions
- n/a (platform incident)
- Exploited in Australia?
- unknown
Primary: BleepingComputer — Times Car ~6.6M accounts (28 Sep 2026) · Vendor: Park24 Group news (operator parent; check for JP/EN incident notice)
