Home › Intelligence › Brief
BREACH BRIEF🟠 High Breach

Times Mobility Car‑Sharing Platform Breach Exposes 6.6 M Accounts, Including 1.6 M Driver’s License Images

Times Mobility disclosed that a breach exposed data linked to 6.6 million user accounts, including 1.6 million driver’s‑license images. The incident demonstrates why continuous privacy‑control assurance and auditable consent processes are essential for regulatory readiness.

LiveThreat™ Intelligence · 📅 October 01, 2026· 📰 hackread.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
hackread.com

Times Mobility Car‑Sharing Platform Breach Exposes 6.6 M Accounts, Including 1.6 M Driver’s License Images

What Happened — A data breach at Times Mobility, the operator of the Japanese car‑sharing service Times Car, disclosed personal information linked to roughly 6.6 million user accounts. The leak includes about 1.6 million records that contain scanned driver’s‑license images and related identity documents.

Why It Matters for Trust & Control Assurance —

  • This incident highlights the need for robust data‑protection controls that continuously monitor who can access sensitive personal identifiers and how that access is logged.
  • It underscores the importance of having auditable privacy‑governance processes (e.g., consent management, DSAR readiness) that can be demonstrated to regulators and partners after a breach.

Who Is Affected — Transportation & logistics firms offering mobility‑as‑a‑service, and any downstream partners that ingest Times Mobility’s user data.

Recommended Actions —

  • Conduct an immediate data‑inventory to confirm what personal identifiers are stored and where they reside.
  • Verify that access to identity documents is restricted to a need‑to‑know basis, encrypted at rest, and fully logged.
  • Review and update consent‑capture mechanisms and DSAR procedures to ensure they meet regulatory expectations.
  • Capture evidence of these controls (access logs, encryption keys, policy documents) for audit readiness.

Technical Notes — The public report does not disclose the exact attack vector; possibilities include a misconfiguration of storage permissions or compromised credentials. The exposed data comprises names, email addresses, phone numbers, and high‑resolution driver’s‑license scans. Source: HackRead

📰 Original Source
https://hackread.com/japanese-car-sharing-site-times-car-data-breach/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · PrivacyOps · CookiePLUS

Data exposure is where consent and DSAR readiness get tested.

When personal data leaks, regulators ask what consent you held and how fast you can answer a subject request. The Verisq AI Trust Operations platform, with CookiePLUS, keeps that posture audit-ready under GDPR and CCPA.

Explore the Verisq AI Trust Operations platform →