LiMP VPN
← All news

Times Car Breach: 6.6M Carsharing Accounts Leaked

Times Car Breach: 6.6M Carsharing Accounts Leaked

In short: On September 28, 2026, Park24, operator of Japan's largest car-sharing service Times Car, confirmed unauthorized access to its web system: around 6.6 million current and former accounts were leaked, and roughly 1.6 million of them included compromised identity-document photos — primarily driver's license images. No payment data was affected, but the fact that scanned official documents ended up in someone else's hands is a different class of problem than a typical email-and-password leak. It's another reminder of how much personal data modern services — from car-sharing apps to connected cars themselves — collect and store just to verify who you are.

What happened

Unauthorized access to the Times Car web system was detected at 9:07 a.m. Japan time on September 25, 2026, and blocked the following day, on September 26. Park24, the parent company and Japan's largest operator of paid parking and car-sharing services, reported the incident to Japan's Personal Information Protection Commission and police, and launched a forensic investigation with external cybersecurity experts.

What data was compromised

The breach affected roughly 6.6 million records — current and former Times Car members, plus users of the corporate Times Business Service program. The leaked data included names, employer names for corporate accounts, addresses, dates of birth, phone numbers, email addresses, membership numbers, driver's license details, and account passwords. Most notably, around 1.6 million records included the actual images of identity-verification documents — driver's license scans, and in some cases utility bills and student ID cards the service had used to verify users at sign-up. Passwords were reportedly stored in a non-recoverable (hashed) format, and the company stated that no credit card data was affected.

Why a document leak is a different kind of risk

A leaked email-and-password pair is fixed by changing the password in a minute. A leaked driver's license scan isn't: it's a persistent identity credential you can't simply "reissue" the way you reset a password. Photos of official documents are ready-made material for identity fraud — opening credit lines, SIM cards, or accounts in someone else's name — and for passing identity checks at other services that accept a document scan as proof. Security researchers commenting on the incident note that the exposure of such images creates an additional, longer-lasting risk compared with a leak of text-only data, even though the company says it currently has no evidence the stolen files have been published or misused.

What to do if you use car-sharing, equipment rental, or similar services

The incident itself happened in Japan, but the risk model is universal: any service that requests a scanned passport or driver's license for identity verification becomes a potential leak point, regardless of country or reputation. If you've received a breach notification from a service like this — or simply aren't sure which documents you've uploaded where over the years — it's worth changing the password everywhere it matched the leaked account, turning on two-factor authentication, and watching closely for attempts to open credit, a SIM card, or a new account in your name. It also helps to periodically review which services actually hold copies of your documents and delete verification data you no longer need there — the same principle covered in our piece on protecting yourself from doxing and deanonymization.

A personal VPN won't prevent a breach of someone else's server, and it can't protect a document scan that's already sitting on their systems — that happens on the company's side, not your device. But it closes a related gap: it encrypts your own traffic while you fill out verification forms or log into an account over public Wi-Fi, keeping that data from being intercepted at the network level. LiMP VPN is a no-logs service for Android, Windows, and Chrome, with plans from 69 ₽/month.

FAQ

Quick answers to the questions that usually come up after news of an identity-document leak like this one.

Sources