← Back to the latest articles
QUESTION 41Society, Data & Privacy

Times Car's Data Breach: 6.6 Million Accounts and the Information That Remains After We Leave

Identity-document data was exposed in approximately 1.6 million accounts. What has been confirmed, what remains uncertain, and why former members matter.

Times Car confirmed exposure of information associated with about 6.6 million accounts, including identity documents in about 1.6 million. We explain immediate steps for affected people and ask what it means for a company to retain data after a member leaves.

As of the evening of September 30, 2026, Japan time. Figures and response plans below reflect Park24's first three notices. The investigation of the cause and the details for each individual continues.

What has been confirmed?

Following unauthorized access to the web system of the Japanese car-sharing service Times Car, parent group Park24 confirmed that a third party obtained information associated with approximately 6.6 million accounts. It subsequently confirmed that identity documents, including driver's-license images, were exposed in approximately 1.6 million accounts. The latter is a subset, not an additional 1.6 million to add to the overall figure. Park24's second notice and third notice

This does not mean that every affected account included a license image. Park24 says it confirmed that credit-card information was not leaked. It also says it has not confirmed public disclosure of the obtained information or misuse attributable to the incident. That is different from saying that no information was taken. Second notice

From suspicion to confirmation

Park24 detected unauthorized access at 9:07 a.m. on September 25 and initially announced a possible leak. It says it blocked the access route and attack-source communications by 7:25 a.m. on September 26, then confirmed that the attacker could no longer access the system through that route. On September 28 it confirmed the acquisition of information and the figure of roughly 6.6 million accounts. On September 29 it specified the roughly 1.6 million accounts whose identity documents were affected and began emailing those members. First notice, second notice, third notice

The scope includes current and former Times Car members, people who applied but never completed enrollment, and current and former Times Business Service members. The published figure counts accounts, not necessarily distinct people. The affected fields differ by account and may include names, addresses, dates of birth, telephone numbers, email addresses, driver's-license information, identity-document images, company departments, password data and linked-service IDs. Park24 says passwords were stored in a form that cannot be restored; it has not confirmed exposure of passwords in readable form. Its third notice names license images, proof-of-address documents, student ID images and family verification documents among the identity-document material. Second notice, third notice

Nine linked-service IDs included identifiers such as WESTER IDs. JR West states that its own system was not breached and that WESTER passwords did not leak through this incident. A linked identifier appearing in Times Car's data is not evidence that a partner's entire system was compromised. Park24, JR West

What should affected people do now?

Park24 began emailing members whose identity documents were confirmed exposed on September 29. It aims to provide each person's more detailed information in approximately two weeks after specialist investigation. No email yet does not, on its own, establish that an account was unaffected. Former members and incomplete applicants are also within the announced scope. Second notice, third notice

  1. Everyone: check the official notices and any individual notification. Open the Times Car site yourself instead of following a link in a message. Keep a copy of any notice and check which fields are said to be involved and when further detail is promised. Park24
  2. Everyone: guard against impersonation. Do not open suspicious links or attachments or give a caller or website your password, verification code or payment details. Park24 says it does not ask for passwords or card information by email, text or telephone. Park24
  3. If you reuse a password: replace it through each service's official site. Give each account a different password and enable multifactor authentication where available. This is a precaution; Park24 has not reported exposure of readable passwords. Park24, Japan's IPA guidance
  4. If identity-document data was exposed: verify the details and watch for suspicious activity. Preserve notices and unexpected contracts, charges or identity-check requests. Contact the relevant provider and the official Times Car inquiry desk about your circumstances. The published telephone line is 0120-25-8924, available around the clock. People in Japan who suspect impersonation or other crime can also seek non-emergency police advice through #9110. Park24, National Police Agency
  5. If you entered data on a fake site: act immediately. Change the password you entered, along with any matching passwords elsewhere, via the official sites. If you entered card information, contact the card issuer promptly. IPA guidance

Park24 says credit-card data was not leaked in this incident. That does not support a blanket instruction for every member to replace a card or driver's license immediately. The appropriate next action depends on each person's notice and circumstances. Second notice

Leaving a service is not the same as leaving its database

The following is this article's interpretation, not a finding about illegality. A car-sharing operator has reason to verify who may drive. But members may think of the license image and address they submit as information belonging to that journey, not to an indefinite relationship with the company. The inclusion of former members and incomplete applicants shows why a person who no longer uses the service may still have a stake in the breach. It does not, by itself, establish that any particular retention period was unlawful. Park24's scope

Philosopher Helen Nissenbaum's idea of contextual integrity understands privacy not merely as keeping data secret, but as whether information flows appropriately within the social context in which it was given. Nissenbaum, Privacy as Contextual Integrity

Submitting an identity document to rent a vehicle and having its image remain after leaving the service are not the same experience for a member. The relevant questions are therefore concrete: Which records need to be retained, for what purposes and for how long? Does the company need to keep the image itself, or would less data suffice? How can a former member understand what remains? These are questions about justification and transparency, not an assumption that all retention is forbidden.

NOW IN QUESTION: when does an account really end?

Park24 says it has not confirmed public release or misuse of the information and is still investigating the cause and scope. It has promised further detail on prevention measures. Clear updates matter: people need to know what was exposed in their case, what action is useful, and what changes as the investigation continues. Park24's second notice

We want a service to recognize us instantly when we need it. We may also want it to forget us when we leave. If closing an account ends only the visible relationship, when—and by whose decision—does the underlying collection of identifying information end?

The deeper question is not only how a company apologizes after a breach. It is who decides what must be remembered, for how long, and how that decision is explained to the people whose information is kept.

Sources: Park24 first notice / second notice / third notice / JR West notice / Nissenbaum paper

SHARE

Share this article

Carry the question into another conversation.

DISCUSSION

Discuss this question

Write in Japanese or English. Comments are translated automatically and shared across both versions of the article.

0/2000 characters

Loading comments…

DISCOVER MORE

What to read next

Explore the same question through other stories and ideas.

Articles attracting attention on NOW IN QUESTION.

  1. 01QUESTION 25What Is Todai Kokugo Kenkyukai? Reviews, Controversy, ‘Suspicious’ and ‘Scam’ Searches—and the Ethics of Selling Exam Anxiety
  2. 02QUESTION 13Why Did Surgery at Kyoto University Hospital Not Stop?
  3. 03QUESTION 18Who Can Stop a Festival That No One Organizes?—Yajū Day and the Protocol Crowd