The Times Car data breach exposed about 6.6 million accounts and ID document images for 1.6 million. What it means for KYC teams that still store ID photos.
Table of contents
The Times Car data breach exposed personal data from about 6.6 million accounts at Park24's Japanese car-sharing service, including identity document images for about 1.6 million. Park24's subsidiary Times Mobility detected the intrusion on 25 September 2026. The leaked images include driver's licences, the photo IDs that image-based eKYC relies on, plus utility bills and student IDs.
- Park24 says a third party accessed the Times CAR web system run by its subsidiary Times Mobility, detected at 9:07 a.m. on 25 September 2026 and blocked by 7:25 a.m. the next day.
- About 6.6 million current and former accounts were affected, including applicants who never finished signing up.
- About 1.6 million accounts lost identity document images: driver's licences, proof-of-address documents, student IDs and family documents.
- Japan's anti-money laundering rules will abolish the online method that relies on a photographed ID document from 1 April 2027, moving regulated firms to IC chip reads.
- Under Japan's privacy law, the final report to the Personal Information Protection Commission is due within 60 days for a leak that may involve a wrongful act.
What happened in the Times Car data breach?
The Times Car data breach began with unauthorised access to the web system behind Times CAR, a car-sharing service run by Times Mobility, a subsidiary of the Tokyo-listed Park24. Park24 has confirmed that about 6.6 million accounts were affected, about 1.6 million of them with identity document images. No credit card data was taken.
Park24's English notice of 28 September 2026 says a third party "viewed or improperly obtained" personal information. Passwords were stored in a non-reversible format, according to the same notice.
Park24 published three Japanese updates in five days. The first notice, on 25 September, reported possible leakage. The second, on 28 September, confirmed about 6.6 million accounts. The third, on 29 September, put the number of accounts with leaked identity documents at about 1.6 million and began emailing those members.
The scope reaches past active customers. The English notice covers current and former members, including "applicants who applied for membership but whose enrollment was not completed." Corporate Times Business Service members are also affected, as are IDs linked to nine partner services, including JR West's WESTER ID.
| Item | Detail | Source |
|---|---|---|
| Detected | 25 September 2026, 9:07 a.m. | Park24 notice, 28 September |
| Contained | 26 September 2026, by 7:25 a.m. | Park24 notice, 28 September |
| Accounts affected | About 6.6 million | Park24 second report |
| Accounts with ID document images | About 1.6 million | Park24 third report |
| Not affected | Credit card data | Park24 notice, 28 September |
| Reported to | Personal Information Protection Commission and police | Park24 notice, 28 September |
The table draws on Park24's own disclosures. Member-level detail is promised within about two weeks of 29 September, after the external forensic review.
Which identity documents leaked, and why do images matter?
In the Times Car data breach, about 1.6 million accounts lost images of identity documents, not just typed data. Park24's third report lists driver's licence images, proof-of-address images such as utility bills, student ID images for the student plan, and family documents for the family plan. An image carries the photo, layout and printed details a forger needs.
That distinction matters for fraud. A typed licence number gives a fraudster digits. A licence image gives them the document itself, which can be reprinted, edited or replayed into any onboarding flow that accepts a photo of a document. The second report also lists names, addresses, dates of birth, phone numbers and email addresses for the wider 6.6 million, enough to make phishing that impersonates Park24 convincing.
Park24 has warned members about messages that pretend to come from the company. It says it found no evidence, as of 28 September, that the data had been published or misused. That is a statement about the first days, not a guarantee. Identity documents stay valid for years, so the window of risk is long.
How does this compare with other identity document breaches in 2026?
The Times Car data breach is smaller than the 153 million scans a seller claimed to hold from IDScan.net, but unusually well quantified. Park24 confirmed both totals in writing within four days. Other 2026 incidents involving identity documents have left the number of images in dispute or exposed numbers rather than images.
| Incident | First public report | Scale | What leaked | Holder |
|---|---|---|---|---|
| Times Car | 25 September 2026 | About 6.6 million accounts, 1.6 million with ID images | Licence, address, student and family document images | Car-sharing operator |
| IDScan.net | 1 September 2026 | Over 153 million scans advertised by a seller, unconfirmed by the company | Names and ID numbers per the company, images per the listing | ID scanning vendor |
| AssuranceAmerica | 8 July 2026 | 6,998,886 people | Names, contact details, driver's licence numbers | Auto insurer |
The pattern across all three is the same. A business collected identity documents for one check and kept them afterwards. Our coverage of the IDScan data breach and the AssuranceAmerica breach has the sources for those rows, and the KYC and IDV breach tracker lists earlier cases.
What does Japan's 2027 eKYC rule change?
From 1 April 2027, Japan's anti-money laundering rules drop the online method built on a selfie plus a photographed photo ID, known as the ho method. The amendment to the Enforcement Regulations of the Act on Prevention of Transfer of Criminal Proceeds was promulgated on 24 June 2025. It is adopted and published but not yet applicable.
The amended Article 6 keeps the selfie method only where the customer also sends the data stored on the IC chip of a photo ID. The National Police Agency's Q&A on the amendment explains the goal: abolishing methods with a high risk of impersonation through forged or altered identity documents. The amended rules keep the postal route only for originals of certain documents with anti-forgery features. The Q&A adds that a copy posted before the change but received after it must be verified again by another method. Accounts opened under the old methods before the change do not need re-verification.
| Remote method for individuals | Until 31 March 2027 | From 1 April 2027 |
|---|---|---|
| Selfie plus a photographed photo ID (ho method) | Permitted | Abolished |
| Selfie plus data read from a photo ID's IC chip | Permitted | Retained |
| Copies of identity documents sent by post | Permitted | Not available |
| Originals of certain identity documents sent by post | Permitted | Retained for documents with anti-forgery features |
Times Mobility is not a regulated business under that Act, so the rule does not bind it. The policy logic still applies: a document image is the evidence most open to forgery, and a leak of 1.6 million images adds to the supply of exactly that material.
What does this mean for your obligations?
The Times Car data breach maps onto five specific duties: breach reporting, security and erasure under Japan's Act on the Protection of Personal Information (APPI), and record-keeping and suspicious transaction reporting under the Act on Prevention of Transfer of Criminal Proceeds. Together they decide what firms keep, for how long, and what they must report.
Breach reporting under APPI Article 26. The Enforcement Rules, Article 7, list four triggers that make a leak reportable. At least two apply here: more than 1,000 people, and a suspected wrongful act. Article 8 requires a prompt preliminary report, then a final report within 30 days, or 60 days for wrongful-act cases. Counting from 25 September, that points to around late November 2026. APPI Article 26(2) also requires notifying the individuals.
Security and vendor oversight under APPI Articles 23 and 25. The Act requires necessary and appropriate measures to prevent leaks, and supervision of any contractor that handles the data. Document images held by an outsourced onboarding provider remain the responsibility of the business that outsourced them.
Erasure under APPI Article 22. A business must endeavour to erase personal data without delay once it no longer needs it. It is a duty to try, not a fixed deadline. Applicants who never completed sign-up are the clearest test of that duty.
Record-keeping under the AML Act. Regulated firms must keep verification records for seven years after the relationship ends, under Article 6(2). The Enforcement Regulations, Article 19, require the selfie and document images from a ho method check to be attached to that record. A firm that used the ho method must keep those images for that full period, even after April 2027. Switching method stops new images accumulating; it does not shorten the retention of old ones.
Suspicious transaction reporting under AML Act Article 8. Regulated firms must report promptly when they suspect property is criminal proceeds. An application that reuses a leaked licence image is a synthetic or impersonation fraud red flag to weigh when deciding whether to file, and a reason to favour eKYC built on chip reads and liveness detection.
What is still uncertain, and what are the risks?
Four questions remain open after Park24's third report: the cause of the intrusion, member-level detail, remedial measures and the financial impact. The main risks are fraud using the 1.6 million images, action by the Personal Information Protection Commission, exposure through nine linked partner services, and a slow move to chip reads outside regulated firms.
The first risk is fraud using the images. Park24 reports no evidence of publication so far, but stolen data can surface long after a breach is disclosed. Japanese firms that still accept photographed documents until 31 March 2027 remain exposed for the whole transition period.
The second risk is regulatory. The Personal Information Protection Commission can give guidance and advice under APPI Article 147, and recommendations and orders under Article 148 for breaches of duties such as security management in Article 23. The erasure duty in Article 22 is an effort duty outside Article 148. Whether the Commission acts here, and whether it comments on keeping data from applicants who never joined, is unknown.
The third risk is liability spread. Nine partner services had IDs linked to Times CAR accounts. Who notifies whom, and whether partners must assess their own exposure, depends on facts not yet public. The fourth is the slow fix: chip-based checks only cover firms subject to the 2027 rule, and many non-regulated businesses will keep photographing licences.
How should compliance teams respond?
Treat the Times Car data breach as a retention audit prompt, not only a security incident. The fastest way to shrink breach impact is to hold fewer identity documents. Start with the records that serve no live purpose, then change how new checks are captured.
Map every place your organisation stores document images, including vendor systems. Purge images for applicants who never onboarded and for closed accounts once your legal retention period ends. Separate the verification record you must keep from the raw image you may not need, noting that in Japan ho method images form part of the record. If you operate in Japan, plan the move from photographed documents to IC chip reads before 1 April 2027. Add the leaked document types to fraud rules, and watch for repeat applications that reuse licence images.
Zyphe was built around holding less. It reads passport NFC chips to ICAO 9303 standards, runs two-step liveness, and encrypts documents into a vault split across nodes, unlockable only with a key the user or customer holds. Your business receives verification results, not a central store of customer PII. See how decentralised PII storage works, or book a demo.
The bottom line
The Times Car data breach shows where identity risk now sits: in the archive of document images that businesses collect for one check and keep for years. Japan's own AML rules are retiring photographed documents for the same reason. Teams that verify identity should read the chip, keep the result, and stop collecting pictures they will be obliged to keep.
Cited sources
- Park24, Notice Regarding Unauthorized Access at a Consolidated Subsidiary's System and Personal Data Breach, 28 September 2026
- Park24, Times CAR web system unauthorised access, third report, 29 September 2026 (Japanese)
- Park24, Times CAR web system unauthorised access, second report, 28 September 2026 (Japanese)
- Park24, Times CAR website possible personal data leak, first report, 25 September 2026 (Japanese)
- Act on the Protection of Personal Information, Articles 22, 23, 25, 26, 147 and 148 (e-Gov, Japanese)
- Enforcement Rules of the Act on the Protection of Personal Information, Articles 7 and 8 (e-Gov, Japanese)
- Enforcement Regulations of the Act on Prevention of Transfer of Criminal Proceeds, Articles 6 and 19 (e-Gov, Japanese)
- National Police Agency, Q&A on the amendment of the Enforcement Regulations, June 2025 (Japanese)
- Act on Prevention of Transfer of Criminal Proceeds, Articles 6 and 8 (e-Gov, Japanese)
Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.