Times Car’ Leaks Over 6.6 Million Personal Records — Including Driver’s License Photos

From our other sites

The story

On September 28, 2026, Park24 announced that up to roughly 6.6 million account records were leaked from its car-sharing service “Times Car” due to unauthorized access. The breach includes names, addresses, and dates of birth, as well as images of driver’s licenses and student IDs submitted for identity verification, and affects accounts of both former members and corporate clients. While no credit card data is confirmed to have leaked, users on 5ch warned that if license numbers and check digits were also exposed, they could be used to forge fake IDs, and many voiced unease that the cause of the leak has not been disclosed.

On the 28th, Park24 announced that its car-sharing service “Times Car” had suffered unauthorized access, leaking personal information from up to roughly 6.6 million accounts, some of which included driver’s license images.

As of now, no misuse of the information has been confirmed, and the service continues to operate. The leak affected up to roughly 6.6 million accounts belonging to Times Car members — including former members — and corporate clients of the Times Business Service.

In addition to names, addresses, dates of birth, phone numbers, and email addresses, the leaked data includes driver’s license details and images of driver’s licenses, student IDs, and other documents submitted for identity verification. No leak of credit card information has been confirmed.

Source: nikkei.com / Original article here

What people said

3AnonymousSep 29, 2026 08:49
6.6 million people's license photos leaking out is insane
6AnonymousSep 29, 2026 08:53
With this, people could forge My Number cards or driver's licenses and basically become 'Japanese' at will
7AnonymousSep 29, 2026 08:54
Fraudulent credit card and phone contract applications using stolen identities are probably about to spike
9AnonymousSep 29, 2026 08:55
Leaking the correct check digit for the license number is the scary part
Swap in a new photo and you've got a perfect forgery
10AnonymousSep 29, 2026 09:00
Was it a hack?
Was security just lax enough to be exploited?
Did an employee lose a PC or USB drive full of data?
Did an employee sell it to a data broker?
11AnonymousSep 29, 2026 09:00
When personal data leaks, victims can file damages lawsuits against the company.
The going rate per person isn't actually that high.
Consolation money tends to run ¥3,000–30,000, plus about ¥5,000 in legal fees.
But if hundreds of thousands of people's data leaked and everyone filed a claim, the total could reach hundreds of millions of yen.
12AnonymousSep 29, 2026 09:04
If scammers start calling pretending to be Times Car saying 'we're wiring you ¥100,000 in compensation, just give us your bank account details,' I bet a ton of people fall for it
13AnonymousSep 29, 2026 09:08
This is what happens when companies casually make people submit photos of their ID documents
14AnonymousSep 29, 2026 09:10
This is exactly why facial recognition [for Hello! Project fan events] is a non-starter
18AnonymousSep 29, 2026 09:24
Is it being targeted because it involves driver's licenses?
What happens if this data ends up overseas?
20AnonymousSep 29, 2026 09:32
That's hell
By rights the damages per person should be in the tens of millions of yen
21AnonymousSep 29, 2026 09:34
Anyone whose data leaked can't use facial recognition anymore unless they get plastic surgery
22AnonymousSep 29, 2026 09:36
Wonder if some of them will end up 'married' without even knowing it
23AnonymousSep 29, 2026 09:38
There's been a string of these lately — Tokyo Metro, Seicomart, and others —
but this one's on a whole different, hopeless level as far as data leaks go
24AnonymousSep 29, 2026 09:38
Driver's license info (number/address/name/DOB/photo) is basically impossible to change
Welp, lol
25AnonymousSep 29, 2026 09:39
Regulators should just assume companies are fundamentally incapable of safely managing personal data and tell them not to store it in the first place
27AnonymousSep 29, 2026 09:42
If you get an individual notice from Times, you might want to immediately flag the possibility of identity misuse to all three credit bureaus — JICC, CIC, and KSC
28AnonymousSep 29, 2026 09:45
Just move, get plastic surgery, and sever the link between your My Number photo and your address
Then hire a lawyer and bill Times for the whole thing
29AnonymousSep 29, 2026 09:48
This is exactly why I still can't bring myself to get a My Number card
31AnonymousSep 29, 2026 09:51
Honestly, who cares that it leaked
This happens somewhere every single day
You're better off just assuming data centers are leaky sieves and living with it
32AnonymousSep 29, 2026 09:55
If you can't manage personal data properly, don't keep it around at all
36AnonymousSep 29, 2026 10:01
Storing that on something that's always network-connected means either there's no security person or they're an idiot
Once it's registered, move it to a separate offline vault
Why can't they even manage that, lol
37AnonymousSep 29, 2026 10:02
Sounds like you can't get through by phone to either Times or CIC right now, lol
38AnonymousSep 29, 2026 10:04
The attackers really know where to strike though
Driver's licenses have everything you need for identity theft all in one place
40AnonymousSep 29, 2026 10:07
Could this end up being the biggest leak on record?
Both in terms of the number of records and how sensitive the data is
41AnonymousSep 29, 2026 10:08
Funny how it always just ends with a 'sorry' no matter how bad the leak is
42AnonymousSep 29, 2026 10:08
@
Got through to the Times Car Share inquiry desk and asked a few things
– The exact number affected is still under investigation; 6.6 million is just the upper bound
– They're still identifying who's affected via logs, etc.
– Affected users will be notified by some method at a later date; they declined to specify the method, citing security reasons
– There's no major difference between what the inquiry desk knows and what's on the official site
43AnonymousSep 29, 2026 10:09
The driver's license is Japan's go-to ID document
With the number, name, DOB, address, and photo all together, that combination is enough to open a bank account, sign a phone contract, pass identity checks at financial institutions, and even rent a car
44AnonymousSep 29, 2026 10:10
What exactly makes people trust a company enough to hand over their info in the first place?
wondered this old-school analog dad
50AnonymousSep 29, 2026 10:15
Same principle as 'you can't put a door on people's mouths' — once it's out, it's out (Japanese proverb about gossip spreading unstoppably)
51AnonymousSep 29, 2026 10:15
Glad I just drive my own kei car instead
53AnonymousSep 29, 2026 10:17
Not just rental cars — any service like this requires handing over your personal info
and yet every single one of them ends up with sloppy data management
54AnonymousSep 29, 2026 10:18
Is Toyota Rent a Car okay, though?

Background and key points

The driver’s license is one of the few official Japanese ID documents that bundles address, date of birth, and photo all in one place, and unlike an email address, its number and contents can’t be changed by the user — which makes this leak especially serious. Concern over the license data was strong enough that the thread produced extreme countermeasures like “get plastic surgery to sever the link.” Meanwhile, it’s worth noting that the cause of the leak (unauthorized access vs. an internal management failure) has not been disclosed, and both the method and timing of notifying victims remain “under investigation.” There has been a string of recent leaks at businesses handling identity documents — Tokyo Metro, Seicomart, Nippon Rent-A-Car, and others — putting the data-handling practices of any service that requires submitting license photos under scrutiny.

*This article is compiled from excerpts and a summary of the 5ch (Hello! Project) thread “‘Times Car’ leaks up to roughly 6.6 million records (names, addresses, dates of birth, phone numbers, email addresses, driver’s licenses, student IDs, etc.).”

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *