Full Report
Japanese car-sharing service Times Car has confirmed that approximately 6.6 million user accounts were compromised in a cyberattack disclosed late last week. [...]
Analysis Summary
# Incident Report: Times Car Massive Data Breach
## Executive Summary
Japanese car-sharing leader Times Car, operated by Times Mobility (Park24 Group), suffered a major cyberattack resulting in the compromise of 6.6 million user accounts. The breach, occurring in early September 2026, involved the exfiltration of highly sensitive personal data, including driver's license images and hashed passwords. While services remain operational, the company is currently undergoing a forensic investigation to determine the exact entry point and mitigate further risk.
## Incident Details
- **Discovery Date:** September 25, 2026
- **Incident Date:** Beginning of September 2026
- **Affected Organization:** Times Car (Times Mobility / Park24 Group)
- **Sector:** Transportation / Car-sharing / Mobility Services
- **Geography:** Japan
## Timeline of Events
### Initial Access
- **Date/Time:** Early September 2026
- **Vector:** Unauthorized third-party access (Specific technical vector undisclosed)
- **Details:** Attackers bypassed security controls to gain access to the primary membership database.
### Lateral Movement
- Details not publicly disclosed; however, the scope suggests movement from initial entry points to centralized databases housing both individual and corporate (Times Business Service) member records.
### Data Exfiltration/Impact
- **Volume:** 6.6 million records (current and former members).
- **Stolen Data:** Full names, physical addresses, DOB, phone numbers, email addresses, driver's license details, images of ID documents, service IDs, and protected (hashed) passwords.
### Detection & Response
- **September 25, 2026:** Unauthorized access detected and publicly disclosed.
- **September 26, 2026:** Times Car successfully blocked the unauthorized access points.
- **September 28, 2026:** Confirmed data theft following an internal and external forensic investigation.
## Attack Methodology
*Note: Based on available public disclosure; specific MITRE ATT&CK mappings are inferred.*
- **Initial Access:** Unauthorized third-party intrusion (potential credential stuffing or vulnerability exploitation).
- **Persistence:** Undisclosed.
- **Privilege Escalation:** Likely achieved to access the high-value membership database.
- **Defense Evasion:** Not disclosed.
- **Credential Access:** Access to account passwords (stored in "unrestorable" format).
- **Discovery:** Internal reconnaissance of member databases and corporate account programs.
- **Collection:** Gathering of PII and identity verification images.
- **Exfiltration:** Large-scale extraction of 6.6 million records.
- **Impact:** Data breach and identity theft risk for millions of users.
## Impact Assessment
- **Financial:** High (potential regulatory fines under APPI, forensic costs, and customer notification expenses).
- **Data Breach:** Critical. 6.6 million records, including government-issued ID images.
- **Operational:** Low. Services reported to be operating as normal.
- **Reputational:** High. Breach affects a significant portion of Japan's car-sharing market.
## Indicators of Compromise
- **Network indicators:** [Not disclosed by Park24 Group at this time]
- **File indicators:** [Not disclosed]
- **Behavioral indicators:** Unusual database queries and high-volume data egress in early September.
## Response Actions
- **Containment:** Blocked unauthorized access on September 26.
- **Eradication:** Forensic investigation ongoing with external security experts to identify and remove persistent threats.
- **Recovery:** Staged notification process for 6.6 million affected individuals.
- **Hardening:** Ongoing review of security architecture and database access controls.
## Lessons Learned
- **Retention Policies:** The inclusion of "former members" in the breach suggests a need for stricter data retention and purging policies for sensitive PII.
- **Monitoring:** The delay between the "beginning of the month" intrusion and late-September detection indicates a need for improved real-time anomaly detection.
- **Encryption:** While passwords were "unrestorable," the accessibility of raw driver's license images suggests a need for stronger encryption-at-rest for media files.
## Recommendations
- **Multi-Factor Authentication (MFA):** Enforce MFA for all user accounts to prevent unauthorized access via compromised credentials.
- **Image Masking/Encryption:** Implement stricter access controls and encryption specifically for identity verification documents.
- **Zero Trust Architecture:** Segment member databases from general web-facing infrastructure.
- **User Guidance:** Advise users to change passwords (due to potential salt/hash cracking attempts) and remain vigilant against phishing using the leaked PII.