Park24’s Times Car breach exposes about 6.6 million accounts, including corporate members and driving-licence images
EditorialBy TrustList Editorial
Park24 told the Tokyo Stock Exchange on 28 September 2026 that attackers reached the web system of its Times Car car-sharing service. About 6.6 million accounts leaked, including Times Business Service corporate members, with licence images.
- Japan
- Tokyo, Japan
- Cybersecurity
- Identity Verification
- +2 more
About Park24’s Times Car breach exposes about 6.6 million accounts, including corporate members and driving-licence images
Park24's Times Car breach exposes about 6.6 million accounts, including corporate members and driving-licence images
28 September 2026 — Park24, the Japanese parking and mobility group listed on the Tokyo Stock Exchange's Prime market, disclosed on 28 September 2026 that a third party gained unauthorised access to the web system of Times Car, the car-sharing service run by its subsidiary Times Mobility, and obtained personal data held by the group.
What happened
- 25 September, 09:07: Times Mobility detected the unauthorised access and began investigating.
- By 26 September, 07:25: the access path was cut and communication with the attacker blocked.
- Park24 has reported the incident to Japan's Personal Information Protection Commission and the police, and an outside firm is carrying out a forensic investigation.
What leaked
About 6.6 million accounts: Times Car members and former members (including people who applied but did not complete registration), and Times Business Service members and former members — the service companies use to give staff access to shared cars.
The data includes name, the department name of corporate members, address, date of birth, phone number, email address, driving-licence details, identity-document information such as driving-licence images, passwords (stored, Park24 says, in a form that cannot be restored) and IDs for nine linked services, including JR West's WESTER ID.
Park24 says credit-card information did not leak, and that it has found no sign so far of the data being published or misused.
Who is affected
Companies in Japan that use Times Business Service for staff travel, their employees, and individual Times Car members. Because licence images and dates of birth were taken, the risk is identity misuse and targeted phishing rather than account takeover.
What to do
- Companies on Times Business Service: tell employees who have used it, warn them about phishing that uses their name, department and booking history, and review who in the company administers the corporate account.
- Watch for Park24's individual notices to affected members.
- If your staff linked other services (such as WESTER ID) to Times Car, advise them to review those accounts.
- For your own vendors: this is the kind of data — licence images and identity documents — that should be minimised or deleted after verification. Ask mobility, travel and HR vendors how long they keep it.
Not yet independently verified. This rests on Park24’s own filing, read in Japanese; no independent report was checked. We will update this when it can be confirmed, and remove this note.
Sources
Categories & features
- Japan
- Tokyo, Japan
- Cybersecurity
- Identity Verification
- Fleet Management Software
- Fleet Management
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More JapanThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.