Skip to content
TrustList
News

Park24’s Times Car breach exposes about 6.6 million accounts, including corporate members and driving-licence images

Editorial

By TrustList Editorial

Park24 told the Tokyo Stock Exchange on 28 September 2026 that attackers reached the web system of its Times Car car-sharing service. About 6.6 million accounts leaked, including Times Business Service corporate members, with licence images.

About Park24’s Times Car breach exposes about 6.6 million accounts, including corporate members and driving-licence images

Park24's Times Car breach exposes about 6.6 million accounts, including corporate members and driving-licence images

28 September 2026 — Park24, the Japanese parking and mobility group listed on the Tokyo Stock Exchange's Prime market, disclosed on 28 September 2026 that a third party gained unauthorised access to the web system of Times Car, the car-sharing service run by its subsidiary Times Mobility, and obtained personal data held by the group.

What happened

  • 25 September, 09:07: Times Mobility detected the unauthorised access and began investigating.
  • By 26 September, 07:25: the access path was cut and communication with the attacker blocked.
  • Park24 has reported the incident to Japan's Personal Information Protection Commission and the police, and an outside firm is carrying out a forensic investigation.

What leaked

About 6.6 million accounts: Times Car members and former members (including people who applied but did not complete registration), and Times Business Service members and former members — the service companies use to give staff access to shared cars.

The data includes name, the department name of corporate members, address, date of birth, phone number, email address, driving-licence details, identity-document information such as driving-licence images, passwords (stored, Park24 says, in a form that cannot be restored) and IDs for nine linked services, including JR West's WESTER ID.

Park24 says credit-card information did not leak, and that it has found no sign so far of the data being published or misused.

Who is affected

Companies in Japan that use Times Business Service for staff travel, their employees, and individual Times Car members. Because licence images and dates of birth were taken, the risk is identity misuse and targeted phishing rather than account takeover.

What to do

  • Companies on Times Business Service: tell employees who have used it, warn them about phishing that uses their name, department and booking history, and review who in the company administers the corporate account.
  • Watch for Park24's individual notices to affected members.
  • If your staff linked other services (such as WESTER ID) to Times Car, advise them to review those accounts.
  • For your own vendors: this is the kind of data — licence images and identity documents — that should be minimised or deleted after verification. Ask mobility, travel and HR vendors how long they keep it.

Not yet independently verified. This rests on Park24’s own filing, read in Japanese; no independent report was checked. We will update this when it can be confirmed, and remove this note.

Sources

Categories & features