Times Car, the Japanese car-sharing service run by Times Mobility, part of the Park24 Group, has confirmed that attackers stole data on about 6.6 million current and former user accounts. The company announced the incident on 25 September and confirmed data theft on 28 September, according to BleepingComputer. Times Car says it has about 4 million active members, 84,000 vehicles and 29,000 stations across Japan's 47 prefectures.
Per the company's statement, the exposed data includes:
The accounts cover both current and former members, including members of the Times Business Service corporate programme. Times Car says the investigation confirmed credit card information was not affected, and that passwords were stored "in a form that cannot be restored." The company did not say whether that means hashing or encryption, so treat that as unverified until a fuller notice is published.
| Date | What happened |
|---|---|
| Early September | A third party accessed Times Car systems, per the company |
| 25 September | Times Car announces the incident and begins investigating |
| 26 September | Unauthorised access blocked |
| 28 September | Company confirms data was stolen |
Taking the company's account at face value, the intruder was in the environment for roughly three weeks before it was cut off. The company has not said how the attacker got in, who they are, or whether ransomware was involved, and a forensic investigation with an outside expert is under way. It says there is currently no evidence the stolen data has been distributed online. Affected customers will be notified individually, in stages, and services continue to operate.
A leaked password can be reset. A driver's licence image cannot. Car-sharing services collect licence photos, and sometimes utility bills or other documents, because they must verify a person before handing over a vehicle. That makes the verification store a concentrated collection of exactly the material criminals use for account-opening fraud and convincing impersonation.
Two consequences follow for anyone holding this kind of data:
After a breach, the people dealing with customers are flooded. Support teams answer thousands of "was I affected?" messages, compliance staff draft notices for regulators, and communications teams revise statements several times a day. Increasingly, those people reach for an AI assistant to move faster, and in a hurry they paste in what they have: customer names, case details, even document excerpts.
That is how a breach about stolen identity data can quietly create a second exposure, this time in a consumer chatbot account nobody governs.
Obichat is a managed chat workspace where teams use multiple AI models inside an organisational boundary rather than through personal accounts. For a breach-response team, the relevant properties are:
Obichat does not stop an attacker from reaching a verification database, and it does not decide how long you keep licence images. Those are controls for your own systems. What it addresses is the downstream habit: the response team needs AI tooling that can be used on sensitive customer material without creating a new, unmonitored copy of it.
If your support team were handling 6.6 million "was my data stolen?" enquiries tomorrow, where would they paste the customer details to draft the replies, and would you know afterwards?
Explore Obichat or talk to us about giving your response and support teams a governed place to work with AI.
Obiguard sits in front of every AI request your organization makes — screening prompts and outputs against the guardrails, compliance frameworks, and audit trails that stories like this one make necessary.
See how it works →