Japanese car-sharing service Times Car has disclosed a data breach affecting over 6.6 million people, hot on the heels of a ransomware attack affecting the country’s railway operator Keio Corporation.
Park24, a parking lot operator, owns Times Car, which has a customer base of over 4 million. Operating in over 47 regions in Japan, the company operates over 84,000 vehicles across 29,000 stations. With annual revenue of $2.6 billion, Keio Corporation manages 85 kilometers of track and operates 69 stations and 25 hotels.
Times Car data breach affects 6.6 million people
On September 25, Times Car disclosed that it had been the victim of a data breach, and on September 29, it promptly blocked the attacker’s access before they could cause further damage.
On September 28, Times Car notified Japan’s Personal Information Protection Commission and announced it would alert the affected individuals. The Commission requires notification within 3 to 5 days if the number of victims exceeds 1,000. The Times Car data breach far exceeds this figure as it affects 6.6 million people. While the company has approximately 4 million customers, the data breach affects current and former customers, as well as individuals who did not complete the sign-up process.
According to the data breach notice, the Times Car data breach leaked personal information, including names, physical addresses, dates of birth, phone numbers, and email addresses. Corporate information, including the victim’s department name, which could enable social engineering attacks, was also exposed.
Other leaked details include account information, such as passwords and linked account IDs. Identity verification documents, including scans of driver’s licenses, were also exposed.
However, financial information including credit card numbers and bank account details was not disclosed. Account passwords that were exposed were also hashed or encrypted using a one-way algorithm such as SHA-256, meaning they could not be reversed, at least not with conventional computing technology, until quantum computers take over.
Nevertheless, the exposure of driver’s license information puts victims at risk of fraud and identity theft. Times Car has launched an investigation and is assessing the impact of the data breach.
“Times Car says the stolen records may include driver’s license information and identity verification documents, including license images,” said Michael Centrella, Head of Public Policy at SecurityScorecard. “That makes this more than a breach of contact details. A password can be changed, but a copy of someone’s identity document can remain useful to criminals long after the initial incident. The company says credit card information was not exposed and that passwords were stored in a form that cannot be recovered. Those are meaningful limits, but they do not remove the risk created by the identity information that was taken.”
Meanwhile, Times Car has advised customers to remain vigilant against potential phishing scams by treating unsolicited text messages, phone calls, and emails from people purporting to represent the company as suspicious. They should also avoid clicking on suspicious links, downloading attachments, or entering personal information on websites without verifying the site’s authenticity.
Ransomware attack hits Japanese railway operator Keio Corporation
Hot on the heels of the Times Car data breach, Japanese railway operator Keio Corporation has disclosed a ransomware attack that disrupted some business operations.
On Saturday, September 26, 2026, Keio Corporation suffered a ransomware attack that disrupted its payment systems, affecting its hospitality business at Keio Plaza Hotel. The company responded by shutting down some systems to contain the ransomware attack and prevent further impacts.
So far, Keio Corporation has not disclosed the identity of the cybercrime gang behind the ransomware attack, and no group has claimed responsibility. Additionally, the company is assessing whether the ransomware attack leaked personal information, and has hired external cybersecurity experts to assist in the investigation. The railway operator has also notified the relevant authorities, including the police.
Nevertheless, the ransomware attack did not disrupt railway operations, and there is no indication that it undermined public safety.
“Keio’s train operations survived this ransomware, and all indicators point to network isolation between the rail systems and the corporate network,” said Denis Calderone, CTO, Suzu Labs. “The hotel reservations, supermarket card payments, bus ticketing, department store loyalty points all went down, indicating at least some level of shared infrastructure.”
“We’re intrigued that there were 3 different Japanese transportation-related incidents (Tokyo Metro had 59,000 member email addresses compromised through a breached vendor server, and Times Car lost data on 6.6 million accounts including driver’s license images) just days before mandatory cyber incident reporting kicks in for critical infrastructure operators,” noted Calderone.
Japan’s transportation sector has experienced a wave of cyberattacks, highlighting the growing threat cyber threats pose to critical infrastructure in the country and worldwide.
On September 27, Tokyo Metro experienced a cyber attack that leaked the email addresses of over 59,000 people who had signed up for the company’s Metpo loyalty scheme.

