Times Car Confirms Data Breach Impacting 6.6 Million User Accounts
What Happened – Times Car, a Japanese car‑sharing platform, disclosed that a third‑party actor accessed its systems in early September 2026. The intrusion led to the theft of personal data for approximately 6.6 million current and former members, including names, addresses, dates of birth, driver‑license images, and account passwords. Credit‑card information was not compromised.
Why It Matters for Trust & Control Assurance
- The incident illustrates a failure in third‑party access controls—a core control objective that continuous assurance programs must monitor and evidence.
- Ongoing vendor‑risk oversight, with real‑time evidence collection, would have highlighted anomalous privileged access before data exfiltration occurred.
- Demonstrable audit‑ready artifacts (e.g., access‑log reviews, third‑party security attestations) are essential to satisfy NIST CSF 2.0 governance and risk requirements after a breach.
Who Is Affected – Transportation & mobility services, corporate fleet‑program participants, and any organization that integrates third‑party mobility platforms for employee travel.
Recommended Actions
- Initiate a forensic review of all third‑party credentials and privileged accounts.
- Verify that passwords are stored using strong, salted hashing; rotate any compromised secrets.
- Strengthen vendor‑risk processes: enforce continuous monitoring, require up‑to‑date security attestations, and map findings to your audit framework.
- Notify affected users per local data‑protection regulations and provide guidance on credential hygiene.
Technical Notes – Attack vector: unauthorized third‑party access (details undisclosed). Exfiltrated data: full name, department (for corporate members), physical address, date of birth, telephone, email, driver‑license images, identity‑verification documents, account password, linked service IDs. No credit‑card data was taken. Source: BleepingComputer