Summary
Times Car, Japan’s largest car-sharing service operated by Times Mobility Inc., has confirmed a data breach affecting approximately 6.6 million user accounts. The breach involved unauthorized access to the Times Car member database and exposed personal information including names, addresses, phone numbers, email addresses, and in some cases payment card details. Times Car has begun notifying affected users and is conducting an investigation with external cybersecurity assistance. The company has not disclosed the attack vector, the threat actor responsible, or the timeframe during which unauthorized access occurred.
Timeline
| Date | Event |
|---|---|
| September 2026 | Unauthorized access to Times Car member database; 6.6 million user accounts affected |
| Sep 27-28, 2026 | Times Car publicly confirms breach; begins user notification; BleepingComputer reports full details |
What Happened
Times Car is Japan’s dominant car-sharing platform, operating across major Japanese cities with a membership base of millions of users. The service collects identity documents, addresses, driving license details, and payment card information standard to transportation subscription services. The 6.6 million affected accounts represent a substantial portion of Times Car’s active membership.
The exposure of payment card details is the most sensitive element of this breach. Members whose payment card information was accessed should contact their card issuers to request new card numbers and monitor statements for unauthorized transactions. Times Car has not confirmed whether the payment card data accessed included full card numbers and CVV codes or only partial data — a material distinction for assessing fraud risk. The breach notification being sent to 6.6 million individuals represents one of the larger personal data exposure events in Japan in 2026. Times Car has not named a threat actor or confirmed whether the breach involved ransomware, targeted intrusion, or exploitation of a specific vulnerability.
Domain Intelligence
timescar.jp — 58.71
timescar.jp scores in the low-trust range at 58.71, carrying a T5_WEAK_CLUSTER flag indicating thin topology representation for this Japanese consumer service domain. Times Car is the breached organization and the party that confirmed the incident and began user notification.
The Trust Observatory · thetrustobservatory.com · September 28, 2026
The Trust Observatory · thetrustobservatory.com · September 8, 2026