Skip to content

Times Car data breach exposes 6.6 mn customer accounts in Japan

Times Car data breach exposes 6.6 mn customer accounts in Japan

Times Mobility, operator of the Times Car Rental car-sharing service, has disclosed a data breach affecting about 6.6 mn current and former customer accounts, including images of personal identification documents.

The company detected unauthorized access on Friday morning and blocked the access route by the following morning. Times Mobility said around 1.6 mn documents were accessed during the incident.

The exposed files included images used to verify customer information, such as utility bills showing home addresses and student IDs submitted by people registering for student plans. Driver’s license images containing personal photographs were also accessed.

The 6.6 mn affected accounts belonged to current and former members of Times Car and Times Business Service. Exposed account information included names, home addresses, telephone numbers and email addresses, although the company said credit card information was not accessed.

An external specialist is conducting a forensic investigation to determine the cause and scope of the incident. The breach to Japan’s Personal Information Protection Commission and police.

PARK24

Security specialists said the exposure of personal photographs creates additional risks because those images could be used in identity theft or attempts to access services requiring identity verification.

The breach has also coincided with a sharp increase in requests from consumers seeking to check or protect their credit information. The Credit Information Center said Tuesday that heavy demand was making it difficult for customers to immediately complete identity verification or review loan and credit disclosures made in their names.

The Japan Credit Information Reference Center reported similar pressure on Wednesday. It said a large number of requests had caused delays and errors in its smartphone application.

Times Mobility said its services continue to operate normally. The company has started contacting users whose information was accessed and warned customers to be cautious about emails, phone calls or messages pretending to come from Times Mobility.

The company said it would not request passwords or credit card information through those channels.

Unauthorized access incidents have increased sharply in Japan. The National Police Agency recorded more than 7,190 cases in 2025, more than four times the number reported in 2021.

Japan has also experienced several large cyber incidents in recent months. A breach involving a government network put information belonging to hundreds of thousands of employees at risk, while a cyberattack on frozen-food logistics company Nichirei disrupted operations affecting restaurants, supermarkets and school lunch programs across the country.