Skip to content

Weekday Japan business intelligence for finance professionals.

Join the list
Tokyo Brief東 京 ブ リ ー フJapan's day, wrapped and delivered by morning.

Article

Park24 Says Times Car Breach Exposed Data From 6.6 Million Accounts

Park24 says a hacker viewed or improperly obtained names, addresses, driver's license images and other data from about 6.6 million Times Car and Times Business Service accounts, but that credit-card numbers were not leaked and passwords were stored in a form the company says cannot be read.

By Tokyo Brief DeskSep 28, 20262 min readPARK24 Co., Ltd.4666
Editorial illustration of a shared car at a curbside car-sharing station with abstract data lines unraveling from its keyless entry box, symbolizing a digital security breach.

Park24, the Tokyo-listed operator of the Times parking and car-sharing network, said a third party broke into the web system behind its Times Car sharing service and viewed or improperly obtained personal data linked to roughly 6.6 million accounts.

The intrusion was detected at 9:07am on September 25, 2026, inside the systems of Times Mobility, the consolidated subsidiary that runs Times Car. A subsequent investigation confirmed that a third party had accessed the system and viewed or improperly acquired part of the personal information the Park24 group holds. The company said it cut off the access route by 7:25am the following morning, September 26, and confirmed the route could no longer be used.

What Park24 says was exposed
Source: PARK24 Co., Ltd. TDnet disclosure, September 28, 2026.
ItemDetail
Accounts affectedApproximately 6.6 million, covering current and former Times Car members (including incomplete sign-ups) and current and former Times Business Service members
Personal data leakedNames, corporate members' department names, addresses, dates of birth, phone numbers, email addresses, driver's license details, identity-document images, passwords, linked-service IDs
Credit card dataNot leaked, according to Park24
PasswordsStored in an unrecoverable format; company has not confirmed exposure in readable form
Linked service IDsNine linked-service IDs, including one for JR West's WESTER ID membership program

The 6.6 million affected accounts span current and former Times Car members, people who applied to join but never completed enrollment, and current and former members of the corporate-focused Times Business Service. The leaked information covers names, the department names of corporate members, addresses, dates of birth, phone numbers, email addresses, driver's license details, images of identity documents such as licenses, passwords, and nine linked-service IDs, including one tied to JR West's WESTER ID membership program.

Park24 said credit-card information was not leaked. Passwords were stored in a format that cannot be restored to readable text, so the company said it has not confirmed the passwords themselves were exposed in a form a third party could read. As of the disclosure, Park24 said it had not confirmed that the leaked data had been made public or misused.

The company has brought in outside forensic specialists to investigate the cause and scope, and has reported the incident to the Personal Information Protection Commission and the police. It plans to notify affected members individually and to publish a follow-up disclosure covering completed and planned recurrence-prevention steps. Park24 said Times Car and its other services continue to operate normally, and that the effect on its earnings is still being assessed; it will disclose promptly if a material impact is identified.