Times Car confirms data breach affecting 6.6 million user accounts
Times Car, a Japanese car-sharing service, confirmed a data breach affecting approximately 6.6 million current and former user accounts. The breach involved unauthorized access to personal information including names, addresses, dates of birth, contact details, driver’s license data, identity verification documents, account passwords (stored in a non-reversible form), and linked service IDs. Credit card information was not compromised. The company blocked access shortly after discovery and is conducting a forensic investigation with external experts. Notifications to affected users are being sent in stages. There is currently no evidence that the stolen data has been distributed online.
AI Analysis
Technical Summary
In early September 2026, unauthorized third parties accessed Times Car's systems, compromising about 6.6 million user accounts encompassing both individual and corporate members. Exposed data includes personal identifiers, contact information, driver’s license and identity verification documents, account passwords stored in a form that cannot be restored (likely hashed or encrypted), and linked service IDs. Credit card data was confirmed unaffected. The company detected and blocked the intrusion by September 26 and is investigating the incident with external forensic assistance. No evidence currently indicates public distribution of the stolen data.
Potential Impact
The breach exposed sensitive personal information of millions of users, including identity documents and account credentials, which could increase the risk of identity theft, phishing, and targeted social engineering attacks. However, credit card information was not compromised, reducing the risk of direct financial fraud from this breach. The exposure of hashed or encrypted passwords still poses a risk if attackers attempt offline cracking. The incident affects both individual and corporate members of Times Car.
Mitigation Recommendations
Times Car has blocked unauthorized access and is conducting a forensic investigation with external experts. Affected users are being notified in stages. Users should remain vigilant against phishing attempts via email, SMS, or phone calls impersonating Times Car and avoid opening suspicious attachments or providing sensitive information. Since passwords were stored in a non-reversible form, users should still consider changing their passwords on Times Car and any other services where they reuse credentials. No official patch or fix applies as this is a breach incident rather than a software vulnerability.
Times Car confirms data breach affecting 6.6 million user accounts
Description
Times Car, a Japanese car-sharing service, confirmed a data breach affecting approximately 6.6 million current and former user accounts. The breach involved unauthorized access to personal information including names, addresses, dates of birth, contact details, driver’s license data, identity verification documents, account passwords (stored in a non-reversible form), and linked service IDs. Credit card information was not compromised. The company blocked access shortly after discovery and is conducting a forensic investigation with external experts. Notifications to affected users are being sent in stages. There is currently no evidence that the stolen data has been distributed online.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In early September 2026, unauthorized third parties accessed Times Car's systems, compromising about 6.6 million user accounts encompassing both individual and corporate members. Exposed data includes personal identifiers, contact information, driver’s license and identity verification documents, account passwords stored in a form that cannot be restored (likely hashed or encrypted), and linked service IDs. Credit card data was confirmed unaffected. The company detected and blocked the intrusion by September 26 and is investigating the incident with external forensic assistance. No evidence currently indicates public distribution of the stolen data.
Potential Impact
The breach exposed sensitive personal information of millions of users, including identity documents and account credentials, which could increase the risk of identity theft, phishing, and targeted social engineering attacks. However, credit card information was not compromised, reducing the risk of direct financial fraud from this breach. The exposure of hashed or encrypted passwords still poses a risk if attackers attempt offline cracking. The incident affects both individual and corporate members of Times Car.
Defensive Guidance
Times Car has blocked unauthorized access and is conducting a forensic investigation with external experts. Affected users are being notified in stages. Users should remain vigilant against phishing attempts via email, SMS, or phone calls impersonating Times Car and avoid opening suspicious attachments or providing sensitive information. Since passwords were stored in a non-reversible form, users should still consider changing their passwords on Times Car and any other services where they reuse credentials. No official patch or fix applies as this is a breach incident rather than a software vulnerability.
Technical Details
- Classification
- {"confidence":0.95,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/times-car-confirms-data-breach-affecting-66-million-user-accounts/","fetched":true,"fetchedAt":"2026-09-28T20:32:50.977Z","wordCount":678}
Threat ID: 6abacef2f7a7c541062ac749
Added to database: 09/28/2026, 20:32:50 UTC
Last enriched: 09/28/2026, 20:32:55 UTC
Last updated: 09/29/2026, 03:36:55 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.