Japanese car-sharing service Times Car, operated by Park24 Group subsidiary Times Mobility, confirmed that unauthorized access to its systems exposed personal information for approximately 6.6 million current and former individual and corporate-program members. The intrusion began in early September 2026, was detected on September 25, and the identified access route was blocked by September 26.
The compromised data includes names and contact details, dates of birth, account and identity-verification information, driver’s-license data, and IDs linked to nine partner services. Passwords were stored in a non-reversible format and no credit-card information was affected. Park24 has notified Japanese privacy regulators and police, retained external forensic specialists, and will contact affected members in stages while warning them of phishing and impersonation via email, SMS, and phone calls.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
Park24 confirmed that the intrusion exposed personal data of approximately 6.6 million Times Car and Times Business Service accounts, including identity, contact, driver-license, verification-document, password, and linked-service ID data. The company said credit-card data was unaffected, reported the incident to Japanese privacy regulators and police, and engaged external forensic specialists.
Times Mobility blocked the identified access route at approximately 7:30 a.m., ending communications with the attacker.
Times Mobility detected unauthorized access to its systems at approximately 9:10 a.m. The company publicly disclosed the incident the same day.
A third party began accessing systems operated by Times Mobility, which runs the Times Car car-sharing service. The intrusion ultimately exposed data associated with current and former individual and corporate-program members.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.