Times Car breach exposes data from about 6.6 million user accounts
The Japanese car-sharing firm is probing the breach and warning affected users to watch for phishing attempts.
Japanese car-sharing provider Times Car has confirmed that a cyberattack in early September led to a data breach affecting about 6.6 million current and former members of its consumer and corporate programs. The company says attackers accessed personal data including names, addresses, dates of birth, contact details, driver’s license information and identity verification documents, as well as account passwords and linked service IDs. Times Car states that passwords were stored in a non-recoverable format and that credit card data was not impacted, and it has not yet seen evidence of the stolen information being shared online. The firm blocked the unauthorized access on September 26 and is running a forensic investigation with external specialists to understand the cause and full scope of the incident. Affected users will receive staged notifications and are being warned to watch for phishing attempts via email, SMS, and phone calls impersonating the company, while Times Car’s mobility services remain operational.
Why it matters
The breach turns a mobility service issue into a long-term personal security concern for millions of people whose identity and contact details are now exposed. Even without credit card leakage or signs of data resale so far, the mix of profile data, documents and account credentials raises the risk of targeted scams and impersonation. How well Times Car handles notifications and containment will shape the fallout for its customers and its reputation.
Signal or noise?
Does this story matter, or is it hype? Decide before you see what everyone else thinks.
Sources
- BleepingComputer