← All news
Data BreachIdentity SecurityAI Security

Times Car Confirms 6.6 Million Accounts Were Stolen, Including Driver's License Images Customers Uploaded to Prove Who They Were

Obiguard Research Team·October 11, 2026·5 min read

Times Car, the Japanese car-sharing service run by Times Mobility, part of the Park24 Group, has confirmed that attackers stole data on about 6.6 million current and former user accounts. The company announced the incident on 25 September and confirmed data theft on 28 September, according to BleepingComputer. Times Car says it has about 4 million active members, 84,000 vehicles and 29,000 stations across Japan's 47 prefectures.

What was taken

Per the company's statement, the exposed data includes:

  • Full name, address, date of birth, telephone number and email address
  • Driver's licence information
  • Identity-verification document information, such as driver's licence images
  • Account passwords
  • Linked service IDs
  • For corporate members, the department name

The accounts cover both current and former members, including members of the Times Business Service corporate programme. Times Car says the investigation confirmed credit card information was not affected, and that passwords were stored "in a form that cannot be restored." The company did not say whether that means hashing or encryption, so treat that as unverified until a fuller notice is published.

The timeline

Date What happened
Early September A third party accessed Times Car systems, per the company
25 September Times Car announces the incident and begins investigating
26 September Unauthorised access blocked
28 September Company confirms data was stolen

Taking the company's account at face value, the intruder was in the environment for roughly three weeks before it was cut off. The company has not said how the attacker got in, who they are, or whether ransomware was involved, and a forensic investigation with an outside expert is under way. It says there is currently no evidence the stolen data has been distributed online. Affected customers will be notified individually, in stages, and services continue to operate.

Why identity documents change the risk

A leaked password can be reset. A driver's licence image cannot. Car-sharing services collect licence photos, and sometimes utility bills or other documents, because they must verify a person before handing over a vehicle. That makes the verification store a concentrated collection of exactly the material criminals use for account-opening fraud and convincing impersonation.

Two consequences follow for anyone holding this kind of data:

  1. Retention is a risk decision. If a verification image is needed once, to check eligibility, keeping it for the life of the account (and after) turns a one-time check into a standing liability. Former members appearing in this breach is a reminder of that.
  2. Phishing follows breaches. Times Car has already warned members to be wary of emails, SMS and phone calls claiming to come from the company, and not to enter passwords or card details in response. With real names, addresses and licence details in criminal hands, those messages can be unusually convincing.

What affected people, and companies like them, should do

  • Treat any message referencing Times Car as suspect unless you started the contact. Go to the service directly rather than following a link.
  • If you reused your Times Car password elsewhere, change it everywhere. Credential stuffing is the fastest way a breach spreads.
  • Companies that collect identity documents should audit where those images live, who and what can read them, and when they are deleted. This includes exports, support tickets and copies pasted into other tools.

The part that is easy to miss: the clean-up workload

After a breach, the people dealing with customers are flooded. Support teams answer thousands of "was I affected?" messages, compliance staff draft notices for regulators, and communications teams revise statements several times a day. Increasingly, those people reach for an AI assistant to move faster, and in a hurry they paste in what they have: customer names, case details, even document excerpts.

That is how a breach about stolen identity data can quietly create a second exposure, this time in a consumer chatbot account nobody governs.

Where Obiguard Obichat fits

Obichat is a managed chat workspace where teams use multiple AI models inside an organisational boundary rather than through personal accounts. For a breach-response team, the relevant properties are:

  • A sanctioned place to draft. Support and communications staff get a workspace set up by the organisation, so the fast path and the approved path are the same one.
  • Workspace and team isolation. Incident conversations stay in the team that owns them, not scattered across personal accounts.
  • Audit trails tied to identity. You can see who used which model and when, which matters when a regulator asks how customer data was handled during the response.

Obichat does not stop an attacker from reaching a verification database, and it does not decide how long you keep licence images. Those are controls for your own systems. What it addresses is the downstream habit: the response team needs AI tooling that can be used on sensitive customer material without creating a new, unmonitored copy of it.

The question to take away

If your support team were handling 6.6 million "was my data stolen?" enquiries tomorrow, where would they paste the customer details to draft the replies, and would you know afterwards?

Explore Obichat or talk to us about giving your response and support teams a governed place to work with AI.

How Obiguard helps

Turn this into enforced policy, not just awareness.

Obiguard sits in front of every AI request your organization makes — screening prompts and outputs against the guardrails, compliance frameworks, and audit trails that stories like this one make necessary.

See how it works →