On September 28, 2026, Park24 announced that the web system of its car-sharing service Times Car had been hit by unauthorized access, and that information from about 6.6 million accounts had been obtained by a third party.

In its first report on September 25, the company said personal information "may have been leaked." Subsequent investigation confirmed that the information was actually obtained by a third party. Those affected include not only current members but also people who have canceled their membership and people who applied to join but never completed the process. The leaked information includes names and addresses, as well as identity documents such as images of driver's licenses.

However, the types of information leaked differ from person to person. To check how you might be affected, it matters not only whether you currently use the service, but also which information you registered in the past and which external services you linked to your account.

AD

About 6.6 million is a count of accounts, and leaked items vary by person

According to Park24's second report, those affected are current Times Car members, former users who have canceled, and people who applied for membership but did not complete the process for some reason.

In addition, for Times Business Service, the corporate offering, both current members and former users are included.

The figure of about 6.6 million refers strictly to the number of leaked accounts. It is not a de-duplicated count of individuals.

The leaked information listed includes names, addresses, dates of birth, phone numbers and email addresses, as well as corporate members' department names, driver's license information, and identity document information such as driver's license images.

Passwords and linked IDs for external services are also included.

However, Park24 states explicitly that this "differs depending on the affected person." It does not mean that every item, including driver's license images, was leaked for all 6.6 million accounts.

The unauthorized access was detected at 9:07 a.m. on September 25. The company began its investigation and response, and by 7:25 a.m. the next day, September 26, it had blocked the intrusion route, cut off communication with the attacker, and confirmed that access was no longer possible after the block.

These times, however, cover the period from detection to completion of countermeasures. They do not indicate when the initial intrusion took place or over what period information was being obtained.

The company says it has confirmed that credit card information was not leaked.

As of the second report, it has also not confirmed that the obtained information has been disclosed to an unspecified number of people, nor any misuse of personal information resulting from this incident.

That said, information not being published online is different from information not having reached a third party. In this case, the acquisition of the information by a third party has been confirmed.

Personal information is retained for about seven years after cancellation

Times Car's official FAQ on cancellation explains that personal information of users who have canceled is kept for "about seven years after cancellation" before being deleted.

The stated reason is a legal obligation to retain transaction records for a certain period. In other words, canceling the service does not mean all of the information you registered is immediately deleted.

This retention policy is important when considering why former members are included in the breach.

However, the "about seven years" in the FAQ is a general retention policy under normal circumstances, and it is not a figure showing how many years' worth of data was leaked this time.

For example, the second report does not say how many years ago a user must have canceled to be included.

Nor can we conclude from the explanation that "transaction records must be retained by law" that retention for the same period is legally required for all personal information, including driver's license images.

It is also unclear how this retention policy for canceled users applies to data of applicants who never completed enrollment.

What will matter to users going forward is not only the general retention period, but an individual explanation of how many types of their information were stored and which of those were obtained this time.

Passwords can be changed, but information once obtained by a third party, such as images of identity documents, cannot be invalidated by changing a password.

That does not mean a license image alone can immediately be used to sign contracts with other companies or impersonate the person. Even so, measures to protect login credentials and measures to prepare for the leak of identity documents need to be considered separately.

AD

WESTER IDs and passwords were affected differently

In its September 25 notice, JR West said that users who had registered a WESTER ID with Times Car may have had their WESTER ID leaked.

At the same time, it said its own systems were not accessed without authorization, and that WESTER passwords managed by JR West were not leaked in this incident.

In other words, the "linked service ID" stored on the Times Car side and the WESTER password managed on the JR West side are treated differently in this breach.

情報の種類 パーク24・JR西日本が公表した状態 利用者が区別したい点
免許証画像などの本人確認書類情報 パーク24の9月28日第2報で漏えい項目に記載 全対象者で同じ情報が漏えいしたわけではない
タイムズカー側のパスワード情報 同第2報で漏えい対象に記載。「復元できない形式」で保存と説明 読み取れるパスワードそのものが漏れたとは確認されていない
タイムズカーに登録したWESTER ID パーク24は連携サービスIDを漏えい対象に記載。JR西日本もWESTER IDが含まれる可能性を案内 WESTER IDの漏えいとJR西日本のシステムへの侵入は別
WESTERのパスワード JR西日本が管理し、本件では流出しないと説明 タイムズカー側のパスワード情報とは保管場所が異なる
クレジットカード情報 パーク24が漏えいしていないことを確認 カード情報が無事でも、他の個人情報への注意は必要

The table organizes, item by item, the "leaked information" and "currently confirmed impact" listed in Park24's second report alongside JR West's announcement. Note that the timing of each announcement and the status of confirmation differ.

The explanation for WESTER also cannot be applied to every other service that was linked to Times Car.

According to Park24, the leaked linked service IDs cover nine types in total, including WESTER ID. The impact on passwords and systems is not necessarily the same for each service.

JR West cautions that even a message containing a user's name or WESTER ID is not necessarily one sent by JR West.

Even if passwords themselves were not leaked, real information such as names and IDs can be used to make fake emails and SMS messages look authentic.

The fact that a linked service's password is protected is a separate matter from whether the user is safe from misuse in phishing and other impersonation.

Even "non-recoverable" passwords depend on how they are stored

Park24 says passwords are stored in a "non-recoverable format," and that there is no risk of accounts being misused with the leaked information.

It also says that, at this point, it has not confirmed that passwords themselves were leaked in a form readable by a third party.

However, the second report does not disclose the specific method used to store passwords.

In general, when passwords are stored as hashes, unlike a scheme in which encrypted passwords can be restored later, a value generated from the entered password is compared with the stored value to verify identity.

But resistance to "offline attacks," in which an attacker computes large numbers of password candidates and checks them against the stored values, varies depending on the method and settings used.

The U.S. National Institute of Standards and Technology (NIST) authentication guidelines call for adding a different "salt" for each account and using a hashing method suited to passwords when storing them.

A "cost factor" is also important: it increases the computation needed to test each candidate so that attackers cannot try large numbers of candidates quickly.

In other words, strictly speaking, "not a mechanism that directly restores the original password" is not the same as "it is sufficiently difficult for a third party to guess candidates."

This, however, is an explanation of general password storage methods, and it does not mean the Times Car password data leaked this time can actually be cracked.

To evaluate Park24's explanation technically from the outside, additional information would be needed on which method and settings were actually used to protect the passwords.

AD

While waiting for individual notices, check through the official site or app

Park24 says it will notify those affected individually and in sequence.

Former members who no longer use Times Car, and people who applied in the past but did not complete enrollment, may also be affected.

Even if you receive a notice, it is safer as a phishing countermeasure to open the official Times Car website or app yourself and check your information, rather than clicking links in emails or SMS messages.

JR West also urges people who use WESTER to access it through the official app or website.

Both Park24 and JR West say they never ask for passwords or credit card information by email, SMS, phone or similar means.

JR West adds that, while the WESTER passwords themselves were not leaked this time, users who reuse the same password on other services should consider changing to a different one.

This does not acknowledge a WESTER password leak; it is a prompt to use this occasion to review password reuse.

Services including Times Car are currently operating as usual.

Park24 is conducting a forensic investigation with external specialists and has reported the incident to the Personal Information Protection Commission and the police. It says it will announce the measures already taken and the medium- to long-term measures to prevent recurrence, along with their timing, in follow-up reports.

What to watch going forward is not only the intrusion route and recurrence prevention.

For former members and applicants who did not complete enrollment, what information was kept, and for how long? What access controls were applied to high-importance data such as identity documents? And what specific information was obtained for each affected person?

Once these points are clarified, users will be better able to look beyond the large figure of "about 6.6 million" and judge concretely how they are affected and what action they need to take.