Times Mobility Car‑Sharing Platform Breach Exposes 6.6 M Accounts, Including 1.6 M Driver’s License Images
What Happened — A data breach at Times Mobility, the operator of the Japanese car‑sharing service Times Car, disclosed personal information linked to roughly 6.6 million user accounts. The leak includes about 1.6 million records that contain scanned driver’s‑license images and related identity documents.
Why It Matters for Trust & Control Assurance —
- This incident highlights the need for robust data‑protection controls that continuously monitor who can access sensitive personal identifiers and how that access is logged.
- It underscores the importance of having auditable privacy‑governance processes (e.g., consent management, DSAR readiness) that can be demonstrated to regulators and partners after a breach.
Who Is Affected — Transportation & logistics firms offering mobility‑as‑a‑service, and any downstream partners that ingest Times Mobility’s user data.
Recommended Actions —
- Conduct an immediate data‑inventory to confirm what personal identifiers are stored and where they reside.
- Verify that access to identity documents is restricted to a need‑to‑know basis, encrypted at rest, and fully logged.
- Review and update consent‑capture mechanisms and DSAR procedures to ensure they meet regulatory expectations.
- Capture evidence of these controls (access logs, encryption keys, policy documents) for audit readiness.
Technical Notes — The public report does not disclose the exact attack vector; possibilities include a misconfiguration of storage permissions or compromised credentials. The exposed data comprises names, email addresses, phone numbers, and high‑resolution driver’s‑license scans. Source: HackRead