Home › Intelligence › Brief
BREACH BRIEF🟠 High Breach

Times Car Confirms Data Breach Affecting 6.6 Million User Accounts

Times Car disclosed that a third‑party breach exposed personal data—including names, addresses, driver’s license images and passwords—of 6.6 million current and former members. The incident underscores the need for robust third‑party access controls and continuous audit evidence to satisfy trust‑and‑control assurance requirements.

LiveThreat™ Intelligence · 📅 September 29, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
4 recommended
📰
Source
bleepingcomputer.com

Times Car Confirms Data Breach Impacting 6.6 Million User Accounts

What Happened – Times Car, a Japanese car‑sharing platform, disclosed that a third‑party actor accessed its systems in early September 2026. The intrusion led to the theft of personal data for approximately 6.6 million current and former members, including names, addresses, dates of birth, driver‑license images, and account passwords. Credit‑card information was not compromised.

Why It Matters for Trust & Control Assurance

  • The incident illustrates a failure in third‑party access controls—a core control objective that continuous assurance programs must monitor and evidence.
  • Ongoing vendor‑risk oversight, with real‑time evidence collection, would have highlighted anomalous privileged access before data exfiltration occurred.
  • Demonstrable audit‑ready artifacts (e.g., access‑log reviews, third‑party security attestations) are essential to satisfy NIST CSF 2.0 governance and risk requirements after a breach.

Who Is Affected – Transportation & mobility services, corporate fleet‑program participants, and any organization that integrates third‑party mobility platforms for employee travel.

Recommended Actions

  • Initiate a forensic review of all third‑party credentials and privileged accounts.
  • Verify that passwords are stored using strong, salted hashing; rotate any compromised secrets.
  • Strengthen vendor‑risk processes: enforce continuous monitoring, require up‑to‑date security attestations, and map findings to your audit framework.
  • Notify affected users per local data‑protection regulations and provide guidance on credential hygiene.

Technical Notes – Attack vector: unauthorized third‑party access (details undisclosed). Exfiltrated data: full name, department (for corporate members), physical address, date of birth, telephone, email, driver‑license images, identity‑verification documents, account password, linked service IDs. No credit‑card data was taken. Source: BleepingComputer

📰 Original Source
https://www.bleepingcomputer.com/news/security/times-car-confirms-data-breach-affecting-66-million-user-accounts/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

Point-in-time vendor reviews miss incidents like this.

Verisq AI Trust Operations replaces the annual questionnaire with continuous third-party monitoring — so vendor exposure becomes audit evidence, not a once-a-year guess.

See how Verisq AI Trust Operations works →