Japanese Car-Sharing Data Breach Impacts 6.6 Million Accounts

www.news4hackers.com-japanese-car-sharing-data-breach-impacts-6-6-million-accounts-japanese-car-sharing-data-breach-impacts-6-6-million-accounts

A cybersecurity incident at a Japanese car-sharing platform has compromised data associated with 6.6 million user accounts, according to a company statement.

Major Data Breach at Japanese Car-Sharing Service Impacts 6.6 Million Users

The breach involves sensitive information such as driver’s license details, identity verification documents, and personal contact data. The affected service, operated by Times Mobility under the Park24 Group, detected unauthorized access to its web systems on September 25. The breach was identified at 9:07 a.m. local time when the company noticed irregular activity. By September 26, Times Mobility had blocked the unauthorized access point and severed communication with the suspected attack source. However, the specific entry vector remains under investigation.

Exposure of Identity Documents and User Information

The compromised data varies per account but includes names, addresses, dates of birth, phone numbers, and driver’s license information. Identity-verification documents, such as utility bills, student IDs, and family verification records, were also accessed in approximately 1.6 million cases. Passwords stored in the system are encrypted in a format that cannot be reversed. Credit card details were not impacted, and there is no evidence of public distribution or misuse of the stolen data. The breach affects current and former users of both the consumer and corporate programs. Corporate accounts may also contain departmental information. Times Mobility has initiated a forensic review with an external cybersecurity firm and notified Japanese regulatory authorities. Affected individuals will be contacted in phases.

Risks of Identity Theft and Phishing Attacks

Security experts warn that the exposure of identity documents poses long-term risks.

Michael Centrella, Head of Public Policy at SecurityScorecard, highlighted that stolen identity information can be exploited for impersonation and fraudulent activities. He noted that while password recovery is not possible, the availability of personal data increases the likelihood of targeted phishing attempts.

Users are advised to remain vigilant against unsolicited communications requesting sensitive information. Times Mobility confirmed its services remain operational but emphasized it will not solicit passwords or financial details through external channels. The incident coincided with heightened activity at Japan’s credit reporting agencies, though no direct link to the breach has been established. The Credit Information Center and Japan Credit Information Reference Center reported technical issues on September 29 and 30, respectively, due to increased traffic. The breach underscores the challenges of securing legacy data, particularly for users who may no longer be active. Centrella pointed out that former members or incomplete registration applicants might not expect their information to remain stored. The incident raises questions about data retention policies and the potential for misuse of historical records. No financial losses have been reported, and the company has not disclosed the method of attack. Affected users are encouraged to monitor their accounts and consider credit monitoring services. The investigation continues to determine the full scope and origin of the breach.



About Author

en_USEnglish