SecurityOctober 2, 20268 min read

What to Do After the Times Car Rental Data Breach

PT

By PrivacyOn Team

Privacy Research & Removal Operations

SharePostFacebookEmail
What to Do After the Times Car Rental Data Breach

Worried you're exposed? Find out in 60 seconds with a free exposure scan.

The Times Car data breach exposed personal information tied to roughly 6.6 million current and former member accounts, including names, addresses, dates of birth, phone numbers, email addresses, driver's license details and images of identity-verification documents. Passwords were stored in non-restorable form and credit card data was not taken. If you ever registered with Times Car, assume phishing attempts are coming.

What Happened

Park24, the Japanese parking and mobility group behind Times Car, detected unauthorized external access to the Times Car web system on September 25, 2026. The company blocked the intruder's access route the following morning and, in a September 28 update, confirmed that data had in fact been stolen. Park24 is running a forensic investigation with outside specialists and notifying affected members in stages while services continue to operate normally.

The headline figure of 6.6 million refers to accounts, not unique people — it spans current and former Times Car (car-sharing and rental) members plus Times Business Service corporate users, so one person with an old membership and a current one may be counted twice.

Why ID Document Images Make This Breach Unusual

Most breaches leak database fields. This one also exposed roughly 1.6 million stored documents, including photographs of the paperwork used to verify identity at signup — driver's licenses, utility bills proving a home address, and student IDs submitted for student plans. A photograph of a government ID is far more useful to a fraudster than a typed license number, because it can be reused to pass document-upload identity checks at other services.

What Data Was Exposed

  • Full name, and department name for corporate members
  • Home address and date of birth
  • Telephone number and email address
  • Driver's license information
  • Identity-verification document details and images, including utility bills and student IDs
  • Account passwords, reportedly stored in a non-restorable (hashed) format
  • Linked service IDs connecting Times accounts to other services

Park24 has stated that credit card information was not compromised. That removes the fastest route to direct financial fraud, but it does not reduce the impersonation risk created by leaked ID images.

Who Is Affected

Anyone who held a Times Car membership — car sharing or rental — including people who cancelled years ago, plus corporate Times Business Service users. Former members are squarely in scope: the company retained ex-member records for years, which is precisely why the count reaches 6.6 million. International travelers who signed up to rent or share a car while in Japan should treat themselves as potentially affected even if they used the service only once.

Step 1: Change Your Password, and Everywhere You Reused It

Park24 says passwords were hashed in a non-restorable format, which makes direct cracking hard but not pointless for weak or common passwords. Change your Times account password now, and more importantly change it anywhere you reused that same password. Use a password manager so each account has a unique credential, and turn on multi-factor authentication on your email account first — email is the master key that resets everything else.

Step 2: Expect Highly Convincing Phishing

Park24 is explicitly warning members about phishing and impersonation by email, SMS, and phone. Attackers holding your name, address, date of birth, and membership history can open a message with details only a real company should know. Treat every unexpected "Times" message as hostile: do not click links in it, navigate to the official site yourself, and never confirm account details, passwords, or one-time codes to an inbound caller.

Is your data already out there?

Leaked data ends up on broker sites and in scammers' hands. Run a free 60-second scan to see your exposure — then let us remove it.

Run a free scan

★★★★★ 4.8/5 · Trusted by thousands of families

Step 3: Protect Against Misuse of Your ID Documents

Because images of licenses and proof-of-address documents were taken, assume someone can present your identity documents in a remote verification flow. Watch for account-opening confirmations, credit inquiries, or verification emails you did not initiate, and report any suspected fraudulent use of your license to your licensing authority straight away. In the US, if your driver's license details are used fraudulently, your state DMV can flag the record and in some states issue a new number; file an identity theft report at IdentityTheft.gov to create the paper trail that unwinds fraudulent accounts.

Step 4: Lock Down Your Credit If You Are in the US

Name, address, date of birth, and ID details are enough for a credit application in many systems. Freezing your credit is free, does not affect your score, and blocks new account openings: freeze at Equifax, Experian, and TransUnion, and consider the secondary bureaus such as Innovis and NCTUE. If your Times membership was tied to a Japanese address, also monitor statements on any payment method you ever linked to the account, even though card numbers were not part of this breach.

Step 5: Watch for Address and Identity Stacking

Breached address and date-of-birth data gets merged with whatever else is already public about you. The more complete that picture, the easier it is for someone to answer a knowledge-based verification question or redirect your mail. Search your own name and see what a stranger can assemble: if people-search sites already publish your current address, phone number, and relatives, the Times data completes a profile rather than starting one.

Shrink What a Breach Can Be Combined With

PrivacyOn removes your personal information from 100+ data brokers and people-search sites, monitors the dark web for your details surfacing in breach dumps, and automatically re-files removals when brokers rebuild your profile. Family plans cover up to five people from $8.33/month. Run a free scan to see what someone holding your Times Car data could still look up about you.

Step 6: Delete Accounts You No Longer Use

The clearest lesson here is retention: this breach was far larger than it needed to be because former members' records — including their ID photographs — were still on file years after they left. Close dormant accounts at services you have stopped using and, where the option exists, explicitly request deletion of stored identity documents rather than simply abandoning the login. Data a company no longer holds cannot be stolen from it.

Frequently Asked Questions

How do I know if I was affected by the Times Car data breach?

Park24 is notifying affected members in stages, so watch for official communication through the Times Car site and your registered email. Because the breach covers current and former members going back years, anyone who ever registered with Times Car or Times Business Service should assume exposure and act now rather than wait for a letter.

How many people were affected by the Times Car breach?

Roughly 6.6 million accounts were affected, which is not the same as 6.6 million people — the figure includes current and former individual members plus corporate Times Business Service users, so some individuals are counted more than once.

Were passwords or credit cards stolen in the Times Car breach?

Park24 reported that account passwords were stored in a non-restorable format and that credit card information was not compromised. Change your password anyway, especially if you reused it elsewhere, because hashed passwords can still be attacked when the original password was weak or common.

What is the risk from leaked driver's license images?

Document images are more dangerous than plain license numbers because they can be submitted to pass photo-based identity verification at banks, crypto exchanges, and mobile carriers. Monitor for accounts opened in your name, report suspected misuse to your licensing authority, and file a report at IdentityTheft.gov if you are in the US.

Should I delete my Times Car account?

Deleting a dormant account is sensible hygiene, but understand its limits — this breach shows that cancelling membership did not stop the company from retaining records, including ID documents, for years. Where you can, ask explicitly for deletion of stored identity documents in addition to closing the account.

How do I reduce my exposure from breaches like this?

You cannot unpublish data a company already lost, but you can shrink everything it gets combined with. PrivacyOn removes your name, address, phone number, and relatives from 100+ data brokers and people-search sites, monitors the dark web for your details in breach dumps, and keeps re-filing removals automatically — a free scan shows your current exposure in minutes.

SharePostFacebookEmail
PT
PrivacyOn Team

Privacy Research & Removal Operations

Operates removal across 100+ data broker sitesGuides verified against live opt-out processesContent reviewed and updated continuously

The team that operates PrivacyOn's data-removal service — publishing opt-out guides and privacy research based on handling real removal requests every day.

Find out what's already exposed

A free 60-second scan shows your breaches and broker exposure. PrivacyOn removes it and monitors 24/7 so it stays gone.

★★★★★ 4.8/5 · Trusted by thousands of families