Free guide: How to use AI in compliance
← Back

The Times Car data breach: 1.6 million ID document images and the case for chip reads

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Published October 3, 2026Reviewed by Charlene Wang
Editorial illustration for the article "The Times Car data breach: 1.6 million ID document images and the case for chip reads".

The Times Car data breach exposed about 6.6 million accounts and ID document images for 1.6 million. What it means for KYC teams that still store ID photos.

Table of contents

The Times Car data breach exposed personal data from about 6.6 million accounts at Park24's Japanese car-sharing service, including identity document images for about 1.6 million. Park24's subsidiary Times Mobility detected the intrusion on 25 September 2026. The leaked images include driver's licences, the photo IDs that image-based eKYC relies on, plus utility bills and student IDs.

  • Park24 says a third party accessed the Times CAR web system run by its subsidiary Times Mobility, detected at 9:07 a.m. on 25 September 2026 and blocked by 7:25 a.m. the next day.
  • About 6.6 million current and former accounts were affected, including applicants who never finished signing up.
  • About 1.6 million accounts lost identity document images: driver's licences, proof-of-address documents, student IDs and family documents.
  • Japan's anti-money laundering rules will abolish the online method that relies on a photographed ID document from 1 April 2027, moving regulated firms to IC chip reads.
  • Under Japan's privacy law, the final report to the Personal Information Protection Commission is due within 60 days for a leak that may involve a wrongful act.

What happened in the Times Car data breach?

The Times Car data breach began with unauthorised access to the web system behind Times CAR, a car-sharing service run by Times Mobility, a subsidiary of the Tokyo-listed Park24. Park24 has confirmed that about 6.6 million accounts were affected, about 1.6 million of them with identity document images. No credit card data was taken.

Park24's English notice of 28 September 2026 says a third party "viewed or improperly obtained" personal information. Passwords were stored in a non-reversible format, according to the same notice.

Park24 published three Japanese updates in five days. The first notice, on 25 September, reported possible leakage. The second, on 28 September, confirmed about 6.6 million accounts. The third, on 29 September, put the number of accounts with leaked identity documents at about 1.6 million and began emailing those members.

The scope reaches past active customers. The English notice covers current and former members, including "applicants who applied for membership but whose enrollment was not completed." Corporate Times Business Service members are also affected, as are IDs linked to nine partner services, including JR West's WESTER ID.

ItemDetailSource
Detected25 September 2026, 9:07 a.m.Park24 notice, 28 September
Contained26 September 2026, by 7:25 a.m.Park24 notice, 28 September
Accounts affectedAbout 6.6 millionPark24 second report
Accounts with ID document imagesAbout 1.6 millionPark24 third report
Not affectedCredit card dataPark24 notice, 28 September
Reported toPersonal Information Protection Commission and policePark24 notice, 28 September

The table draws on Park24's own disclosures. Member-level detail is promised within about two weeks of 29 September, after the external forensic review.

Which identity documents leaked, and why do images matter?

In the Times Car data breach, about 1.6 million accounts lost images of identity documents, not just typed data. Park24's third report lists driver's licence images, proof-of-address images such as utility bills, student ID images for the student plan, and family documents for the family plan. An image carries the photo, layout and printed details a forger needs.

That distinction matters for fraud. A typed licence number gives a fraudster digits. A licence image gives them the document itself, which can be reprinted, edited or replayed into any onboarding flow that accepts a photo of a document. The second report also lists names, addresses, dates of birth, phone numbers and email addresses for the wider 6.6 million, enough to make phishing that impersonates Park24 convincing.

Park24 has warned members about messages that pretend to come from the company. It says it found no evidence, as of 28 September, that the data had been published or misused. That is a statement about the first days, not a guarantee. Identity documents stay valid for years, so the window of risk is long.

How does this compare with other identity document breaches in 2026?

The Times Car data breach is smaller than the 153 million scans a seller claimed to hold from IDScan.net, but unusually well quantified. Park24 confirmed both totals in writing within four days. Other 2026 incidents involving identity documents have left the number of images in dispute or exposed numbers rather than images.

IncidentFirst public reportScaleWhat leakedHolder
Times Car25 September 2026About 6.6 million accounts, 1.6 million with ID imagesLicence, address, student and family document imagesCar-sharing operator
IDScan.net1 September 2026Over 153 million scans advertised by a seller, unconfirmed by the companyNames and ID numbers per the company, images per the listingID scanning vendor
AssuranceAmerica8 July 20266,998,886 peopleNames, contact details, driver's licence numbersAuto insurer

The pattern across all three is the same. A business collected identity documents for one check and kept them afterwards. Our coverage of the IDScan data breach and the AssuranceAmerica breach has the sources for those rows, and the KYC and IDV breach tracker lists earlier cases.

What does Japan's 2027 eKYC rule change?

From 1 April 2027, Japan's anti-money laundering rules drop the online method built on a selfie plus a photographed photo ID, known as the ho method. The amendment to the Enforcement Regulations of the Act on Prevention of Transfer of Criminal Proceeds was promulgated on 24 June 2025. It is adopted and published but not yet applicable.

The amended Article 6 keeps the selfie method only where the customer also sends the data stored on the IC chip of a photo ID. The National Police Agency's Q&A on the amendment explains the goal: abolishing methods with a high risk of impersonation through forged or altered identity documents. The amended rules keep the postal route only for originals of certain documents with anti-forgery features. The Q&A adds that a copy posted before the change but received after it must be verified again by another method. Accounts opened under the old methods before the change do not need re-verification.

Remote method for individualsUntil 31 March 2027From 1 April 2027
Selfie plus a photographed photo ID (ho method)PermittedAbolished
Selfie plus data read from a photo ID's IC chipPermittedRetained
Copies of identity documents sent by postPermittedNot available
Originals of certain identity documents sent by postPermittedRetained for documents with anti-forgery features

Times Mobility is not a regulated business under that Act, so the rule does not bind it. The policy logic still applies: a document image is the evidence most open to forgery, and a leak of 1.6 million images adds to the supply of exactly that material.

What does this mean for your obligations?

The Times Car data breach maps onto five specific duties: breach reporting, security and erasure under Japan's Act on the Protection of Personal Information (APPI), and record-keeping and suspicious transaction reporting under the Act on Prevention of Transfer of Criminal Proceeds. Together they decide what firms keep, for how long, and what they must report.

Breach reporting under APPI Article 26. The Enforcement Rules, Article 7, list four triggers that make a leak reportable. At least two apply here: more than 1,000 people, and a suspected wrongful act. Article 8 requires a prompt preliminary report, then a final report within 30 days, or 60 days for wrongful-act cases. Counting from 25 September, that points to around late November 2026. APPI Article 26(2) also requires notifying the individuals.

Security and vendor oversight under APPI Articles 23 and 25. The Act requires necessary and appropriate measures to prevent leaks, and supervision of any contractor that handles the data. Document images held by an outsourced onboarding provider remain the responsibility of the business that outsourced them.

Erasure under APPI Article 22. A business must endeavour to erase personal data without delay once it no longer needs it. It is a duty to try, not a fixed deadline. Applicants who never completed sign-up are the clearest test of that duty.

Record-keeping under the AML Act. Regulated firms must keep verification records for seven years after the relationship ends, under Article 6(2). The Enforcement Regulations, Article 19, require the selfie and document images from a ho method check to be attached to that record. A firm that used the ho method must keep those images for that full period, even after April 2027. Switching method stops new images accumulating; it does not shorten the retention of old ones.

Suspicious transaction reporting under AML Act Article 8. Regulated firms must report promptly when they suspect property is criminal proceeds. An application that reuses a leaked licence image is a synthetic or impersonation fraud red flag to weigh when deciding whether to file, and a reason to favour eKYC built on chip reads and liveness detection.

What is still uncertain, and what are the risks?

Four questions remain open after Park24's third report: the cause of the intrusion, member-level detail, remedial measures and the financial impact. The main risks are fraud using the 1.6 million images, action by the Personal Information Protection Commission, exposure through nine linked partner services, and a slow move to chip reads outside regulated firms.

The first risk is fraud using the images. Park24 reports no evidence of publication so far, but stolen data can surface long after a breach is disclosed. Japanese firms that still accept photographed documents until 31 March 2027 remain exposed for the whole transition period.

The second risk is regulatory. The Personal Information Protection Commission can give guidance and advice under APPI Article 147, and recommendations and orders under Article 148 for breaches of duties such as security management in Article 23. The erasure duty in Article 22 is an effort duty outside Article 148. Whether the Commission acts here, and whether it comments on keeping data from applicants who never joined, is unknown.

The third risk is liability spread. Nine partner services had IDs linked to Times CAR accounts. Who notifies whom, and whether partners must assess their own exposure, depends on facts not yet public. The fourth is the slow fix: chip-based checks only cover firms subject to the 2027 rule, and many non-regulated businesses will keep photographing licences.

How should compliance teams respond?

Treat the Times Car data breach as a retention audit prompt, not only a security incident. The fastest way to shrink breach impact is to hold fewer identity documents. Start with the records that serve no live purpose, then change how new checks are captured.

Map every place your organisation stores document images, including vendor systems. Purge images for applicants who never onboarded and for closed accounts once your legal retention period ends. Separate the verification record you must keep from the raw image you may not need, noting that in Japan ho method images form part of the record. If you operate in Japan, plan the move from photographed documents to IC chip reads before 1 April 2027. Add the leaked document types to fraud rules, and watch for repeat applications that reuse licence images.

Zyphe was built around holding less. It reads passport NFC chips to ICAO 9303 standards, runs two-step liveness, and encrypts documents into a vault split across nodes, unlockable only with a key the user or customer holds. Your business receives verification results, not a central store of customer PII. See how decentralised PII storage works, or book a demo.

The bottom line

The Times Car data breach shows where identity risk now sits: in the archive of document images that businesses collect for one check and keep for years. Japan's own AML rules are retiring photographed documents for the same reason. Teams that verify identity should read the chip, keep the result, and stop collecting pictures they will be obliged to keep.

Cited sources

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.

Frequently Asked Questions

Park24 says about 6.6 million accounts were affected. Exposed data includes names, addresses, dates of birth, phone numbers, email addresses, driver's licence information, passwords stored in a non-reversible format and linked partner IDs. About 1.6 million accounts also lost identity document images, including driver's licences, proof-of-address documents, student IDs and family documents. Credit card data was not affected.

Times Mobility, Park24's subsidiary, detected the unauthorised access at 9:07 a.m. on 25 September 2026. The access route and attacker communications were blocked by 7:25 a.m. on 26 September. Park24 confirmed the 6.6 million total on 28 September and the 1.6 million document image figure on 29 September 2026.

Yes. Park24's English notice says affected customers include applicants who applied for membership but never completed enrolment, as well as former members and corporate Times Business Service members. That makes the breach a test case for erasing identity data that no longer serves a purpose, which APPI Article 22 asks businesses to attempt.

For businesses regulated under the Act on Prevention of Transfer of Criminal Proceeds, the online method based on a photographed ID document plus a selfie is abolished from 1 April 2027. The selfie method continues only with data read from a photo ID's IC chip. The amendment was promulgated on 24 June 2025.

Inventory every stored document image, including copies held by vendors. Delete images for abandoned applications and closed accounts once retention periods end. Keep the verification record rather than the raw image where the law allows. Move document checks towards IC chip reads with liveness, and add the leaked document types to fraud monitoring.

See privacy-first KYC in action

Verify identity without a central store of documents. Reusable credentials, an exportable audit trail, and a 15-minute integration.

Book a demo