A Japanese Car-Sharing App Just Confirmed 6.6 Million Accounts Were Exposed

Times Car, a major Japanese car-sharing service, confirmed an attacker had access to its systems for nearly a month, exposing driver's license data and passwords for 6.6 million accounts.

Get a summary in:
Traffic surveillance cameras mounted on a roadside pole
Follow Teck Hustlers on Google
Add Teck Hustlers as a preferred source to see more of our stories in Google Top Stories.
Add as preferred source on Google
AA

Admin Alex
Writer
MA

M.Ali
Fact-Checker

Published: October 3, 2026 · Last updated: October 3, 2026

TL;DR: Times Car, one of Japan’s largest car-sharing services, confirmed a breach exposing names, addresses, driver’s license images, and passwords for roughly 6.6 million accounts after an attacker had access for nearly a month.

Highway traffic at night, representing a car-sharing service's digital infrastructure

Nearly a month. That’s how long an attacker reportedly sat inside Times Car’s systems before anyone caught them.

Times Car, one of Japan’s largest car-sharing services, confirmed this week that a data breach exposed information tied to roughly 6.6 million user accounts. According to the company’s own disclosure, an unauthorized party had access to its systems for close to a month before the intrusion was identified and shut down. The exposed data is about as comprehensive as a breach gets: full names, physical addresses, phone numbers, email addresses, dates of birth, driver’s license details, images of identity verification documents, account passwords, and linked service IDs. For corporate members, department names were also exposed.

What makes this particular combination of exposed data worse than a typical breach is the overlap between categories that are individually bad and categories that are catastrophic together. A leaked password is a problem you can fix by changing it. A leaked driver’s license image, tied to a real name, a real date of birth, and a real address, isn’t something you can rotate the way you’d rotate a password. Identity verification documents exist specifically to prove someone is who they say they are, which makes them unusually valuable to anyone running identity theft or account takeover schemes at scale, and unusually hard for the affected person to simply replace.

Car-sharing services sit on an interesting pile of sensitive data precisely because they’re built around verifying that a renter is a real, licensed driver before handing over a car. That verification requirement, reasonable and necessary for the service to function at all, also means a breach at a company like Times Car exposes exactly the kind of document scans that are hardest for a user to protect through normal account hygiene. Changing a password takes thirty seconds. Replacing a driver’s license, or convincing every institution that might encounter a leaked copy of yours that it’s been compromised, takes considerably longer.

Japan has its own data protection framework, administered by the Personal Information Protection Commission, which requires companies to report breaches of this scale and generally expects notification to affected users within a defined window. Whether Times Car’s roughly month-long detection gap draws regulatory scrutiny beyond the breach itself is still an open question; detection speed, not just the breach itself, is increasingly a factor regulators weigh when deciding how hard to come down on a company.

For the 6.6 million people affected, the practical advice is the same as it always is after a breach like this, even though it’s never fully satisfying. Change the password immediately, and change it everywhere else it was reused. Watch for unusual activity on any account tied to the same email address. For the driver’s license and identity document exposure specifically, there isn’t a clean fix, just heightened vigilance for identity theft attempts that could surface weeks or months down the line, long after the initial breach has stopped being news.

Related: A Tech Company Owner Is Accused of Smuggling $300 Million in Nvidia Chips to China and AI Coding Agents Quietly Leaked 13,000 Screenshots From 343 Companies, and Nobody Told Them To.

Bottom Line: A month is a long time for an attacker to sit inside a system holding 6.6 million people’s identity documents. The password half of this breach is fixable in a day. The driver’s license half isn’t fixable at all, and that’s the part worth remembering the next time a service asks to scan your ID.

Follow Teck Hustlers: Facebook · X · Instagram · LinkedIn · TikTok · Pinterest

Follow Teck Hustlers on Google
Add Teck Hustlers as a preferred source to see more of our stories in Google Top Stories.
Add as preferred source on Google