Park24, the Tokyo-listed operator of the Times parking and car-sharing network, said a third party broke into the web system behind its Times Car sharing service and viewed or improperly obtained personal data linked to roughly 6.6 million accounts.
The intrusion was detected at 9:07am on September 25, 2026, inside the systems of Times Mobility, the consolidated subsidiary that runs Times Car. A subsequent investigation confirmed that a third party had accessed the system and viewed or improperly acquired part of the personal information the Park24 group holds. The company said it cut off the access route by 7:25am the following morning, September 26, and confirmed the route could no longer be used.
| Item | Detail |
|---|---|
| Accounts affected | Approximately 6.6 million, covering current and former Times Car members (including incomplete sign-ups) and current and former Times Business Service members |
| Personal data leaked | Names, corporate members' department names, addresses, dates of birth, phone numbers, email addresses, driver's license details, identity-document images, passwords, linked-service IDs |
| Credit card data | Not leaked, according to Park24 |
| Passwords | Stored in an unrecoverable format; company has not confirmed exposure in readable form |
| Linked service IDs | Nine linked-service IDs, including one for JR West's WESTER ID membership program |
The 6.6 million affected accounts span current and former Times Car members, people who applied to join but never completed enrollment, and current and former members of the corporate-focused Times Business Service. The leaked information covers names, the department names of corporate members, addresses, dates of birth, phone numbers, email addresses, driver's license details, images of identity documents such as licenses, passwords, and nine linked-service IDs, including one tied to JR West's WESTER ID membership program.
Park24 said credit-card information was not leaked. Passwords were stored in a format that cannot be restored to readable text, so the company said it has not confirmed the passwords themselves were exposed in a form a third party could read. As of the disclosure, Park24 said it had not confirmed that the leaked data had been made public or misused.
The company has brought in outside forensic specialists to investigate the cause and scope, and has reported the incident to the Personal Information Protection Commission and the police. It plans to notify affected members individually and to publish a follow-up disclosure covering completed and planned recurrence-prevention steps. Park24 said Times Car and its other services continue to operate normally, and that the effect on its earnings is still being assessed; it will disclose promptly if a material impact is identified.
