From our other sites
The story
On September 28, 2026, Park24 announced that up to roughly 6.6 million account records were leaked from its car-sharing service “Times Car” due to unauthorized access. The breach includes names, addresses, and dates of birth, as well as images of driver’s licenses and student IDs submitted for identity verification, and affects accounts of both former members and corporate clients. While no credit card data is confirmed to have leaked, users on 5ch warned that if license numbers and check digits were also exposed, they could be used to forge fake IDs, and many voiced unease that the cause of the leak has not been disclosed.
On the 28th, Park24 announced that its car-sharing service “Times Car” had suffered unauthorized access, leaking personal information from up to roughly 6.6 million accounts, some of which included driver’s license images.
As of now, no misuse of the information has been confirmed, and the service continues to operate. The leak affected up to roughly 6.6 million accounts belonging to Times Car members — including former members — and corporate clients of the Times Business Service.
In addition to names, addresses, dates of birth, phone numbers, and email addresses, the leaked data includes driver’s license details and images of driver’s licenses, student IDs, and other documents submitted for identity verification. No leak of credit card information has been confirmed.
Source: nikkei.com / Original article here
What people said
Swap in a new photo and you've got a perfect forgery
Was security just lax enough to be exploited?
Did an employee lose a PC or USB drive full of data?
Did an employee sell it to a data broker?
The going rate per person isn't actually that high.
Consolation money tends to run ¥3,000–30,000, plus about ¥5,000 in legal fees.
But if hundreds of thousands of people's data leaked and everyone filed a claim, the total could reach hundreds of millions of yen.
What happens if this data ends up overseas?
By rights the damages per person should be in the tens of millions of yen
but this one's on a whole different, hopeless level as far as data leaks go
Welp, lol
Then hire a lawyer and bill Times for the whole thing
This happens somewhere every single day
You're better off just assuming data centers are leaky sieves and living with it
Once it's registered, move it to a separate offline vault
Why can't they even manage that, lol
Driver's licenses have everything you need for identity theft all in one place
Both in terms of the number of records and how sensitive the data is
Got through to the Times Car Share inquiry desk and asked a few things
– The exact number affected is still under investigation; 6.6 million is just the upper bound
– They're still identifying who's affected via logs, etc.
– Affected users will be notified by some method at a later date; they declined to specify the method, citing security reasons
– There's no major difference between what the inquiry desk knows and what's on the official site
With the number, name, DOB, address, and photo all together, that combination is enough to open a bank account, sign a phone contract, pass identity checks at financial institutions, and even rent a car
wondered this old-school analog dad
and yet every single one of them ends up with sloppy data management
Background and key points
The driver’s license is one of the few official Japanese ID documents that bundles address, date of birth, and photo all in one place, and unlike an email address, its number and contents can’t be changed by the user — which makes this leak especially serious. Concern over the license data was strong enough that the thread produced extreme countermeasures like “get plastic surgery to sever the link.” Meanwhile, it’s worth noting that the cause of the leak (unauthorized access vs. an internal management failure) has not been disclosed, and both the method and timing of notifying victims remain “under investigation.” There has been a string of recent leaks at businesses handling identity documents — Tokyo Metro, Seicomart, Nippon Rent-A-Car, and others — putting the data-handling practices of any service that requires submitting license photos under scrutiny.
*This article is compiled from excerpts and a summary of the 5ch (Hello! Project) thread “‘Times Car’ leaks up to roughly 6.6 million records (names, addresses, dates of birth, phone numbers, email addresses, driver’s licenses, student IDs, etc.).”
Leave a Reply