DEV Community

Cover image for Times Car Data Breach Exposed 6.6 Million Accounts. Here's What to Do
Ahsan Luqman
Ahsan Luqman

Posted on Originally published at aliasfleet.com

Times Car Data Breach Exposed 6.6 Million Accounts. Here's What to Do

Times Car Data Breach Exposed 6.6 Million Accounts. Here's What to Do

Times Car confirmed attackers stole 6.6 million accounts, including emails and driver's licence images. Here is what was taken and what to do.

I run AliasFleet, an email alias service. It gives every website its own email address, so when a site is breached, the leaked address belongs to that site alone and you can pause it in one click. Times Car is the newest reason that matters: the Japanese car-sharing service confirmed this week that attackers stole data from 6.6 million accounts.

What came out is worse than the usual list: not just email addresses, but full names, home addresses, dates of birth and photographs of driver's licences. If you have ever used Times Car, or held a Times Business Service corporate account, your details may be in that set. First, though, the facts.

What happened

When was Times Car breached?

Times Car says a third party reached its systems at the beginning of September 2026, and the company announced the incident on 25 September, blocked the unauthorised access the next day, and said it was investigating whether personal information had been taken. An update reported on 28 and 29 September changed that: the theft was confirmed. BleepingComputer and SC Media both covered the confirmation, and their numbers agree.

The official Park24 notice on the Times Car breach, the second report published on 28 September 2026, confirming the investigation results

The affected accounts number about 6.6 million: current and former Times Car members, plus current and former members of the Times Business Service corporate programme. Times Car claims 4 million active members as of August 2026, which means the 6.6 million figure includes people who left years ago. That is normal in breaches, and it is also the point. An old account does not stop being your data the day you stop using the service.

The company says all services continue to operate as normal, and a forensic investigation with an outside expert is under way. Affected customers will be notified individually, in stages.

What was taken

What data did the Times Car breach expose?

The company lists names, physical addresses, dates of birth, telephone numbers, email addresses, driver's licence information including images of identity-verification documents, account passwords, and linked service IDs. Corporate members lost their department names as well. Credit card details were not affected, and the company says there is no evidence the stolen data has been distributed online yet.

Slow down on the licence images, because that is where this breach stops being routine. A leaked password you can fix in a minute. A leaked email address is mostly a spam and phishing problem. A photograph of your driver's licence, sitting next to your name, home address and date of birth, is raw material for impersonating you to a bank, a mobile carrier, or another car service. You cannot rotate your date of birth. You cannot reissue your face.

Corporate members have an extra problem: their department names were taken too, so an attacker does not just know that you work somewhere, he knows where, and in which team. A message that names your employer, your department and your car service is not a generic lure. It is a spear built from this breach alone.

The passwords, at least, were stored in a form the company says cannot be restored, which usually means hashed or encrypted, and that is better than the alternative. If the hashing holds up, nobody is logging into your Times Car account from the stolen file. The risk sits elsewhere. It sits in messages that pretend to come from Times Car.

The messages are the risk

Times Car has warned members to watch for emails, text messages and phone calls claiming to come from the company, and to avoid attachments and any page that asks for passwords or card details. That warning is the whole ballgame. Whoever holds this database has what a convincing fake needs: your real name, your real address, and proof that you are a Times Car member. A message saying your licence verification needs updating is not speculation. It is the obvious next move for anyone holding that data.

How do I tell a real Times Car notice from a fake one?

Mostly, you cannot, and that is the honest answer. Times Car is notifying people in stages, so a genuine notice may arrive weeks from now and look exactly like the phishing it warns against. The rule that survives this: never follow a link in any message about this breach. Open your browser and type the company's real address yourself, then log in there. Check the company's official announcements, and if you are still unsure, contact Times Car through the support channels on that site. If the message was fake, the scammer got nothing. Your click was the thing he needed.

I do not know when the phishing starts, or whether this data stays quiet. "No evidence of distribution" describes last week. It makes a poor promise about next month.

What to do now

What should I do if my data was in the Times Car breach?

Three things, in order. Change your Times Car password first, and change it anywhere you reused it, because credential stuffing is how one breach quietly becomes five; then treat every Times Car message as hostile until you have confirmed it on the company's real site, never through a link in the message. Then check Have I Been Pwned over the coming weeks: this breach has not been indexed there yet, but once it is, an address lookup will tell you whether you were in it. For the longer version of the post-breach routine, the checklist for when your email turns up in a breach covers passwords, freezes and the rest without my repeating it here.

If the identity documents worry you, and they should, call your bank's fraud team. Ask what extra checks they can put on your accounts. Where your country offers identity monitoring or a credit freeze equivalent, this is the week to use it.

Make the next breach harmless

None of the above gives you back the licence images. What the steps can do is change what the next breach takes from you. Every service you sign up for is a database that someone, someday, will copy, and the only variable you control is which address sits in it.

Give each service its own email alias. The mail still lands in your normal inbox. But when that service is breached, the address in the dump belongs to that service alone. You know who leaked it, because only one place ever had that address. You pause the alias and the phishing dies with it, while your bank, your employer and your family keep using an address nobody breached. That is what AliasFleet does, and setting up your first alias takes about thirty seconds per service. If you are tracing an older leak, the method for finding out which website leaked your email goes deeper.

One honest limitation

An alias does not un-leak a driver's licence, and nothing in this article does that either. What was taken from Times Car is taken. The alias only decides the size of the next incident: one address, tied to one service, that you can switch off. Anyone who promises you more than that is selling something.

You cannot stop companies being breached. You can stop being the person whose real inbox sits in every one of them.

Top comments (0)