Times Mobility: Times Car Breach Hits 6.6M Accounts, Keio Ransomware [2026]

Times Mobility: Times Car Breach Hits 6.6M Accounts, Keio Ransomware [2026]

Japan’s Transportation Sector Hit by Dual Cybersecurity Incidents in Late September 2026

In a 24-hour span in late September 2026, two major Japanese transportation entities Times Car, a car-sharing platform, and Keio Corporation, a leading railway operator confirmed separate cybersecurity incidents, exposing vulnerabilities in the country’s mobility sector.

Times Car Breach: 6.6 Million Accounts Compromised

On September 25, 2026, Times Mobility (a subsidiary of Park24) disclosed that an unauthorized third party accessed its systems, affecting 6.6 million current and former users. Of these, 1.6 million accounts included identity-verification documents, such as driver’s license images a particularly high-risk data type due to its potential use in identity fraud.

Exposed data includes:

  • Names, addresses, phone numbers, and email addresses
  • Dates of birth and membership numbers
  • Driver’s license details and linked-service IDs
  • Account passwords

While Park24 has not confirmed any fraudulent use of the data, the breach ranks among Japan’s largest consumer-data incidents of 2026, comparable to Denmark’s 8.8 million-record CPR breach. The inclusion of unresettable identity documents heightens long-term risks for affected users.

Keio Corporation Hit by Ransomware

A day later, on September 26, 2026, Keio Corporation confirmed a ransomware attack, though railway operations remained unaffected. The company isolated affected network segments, suggesting the attack targeted back-office systems rather than operational technology. Some business systems, including sales and reservations at affiliated companies, reportedly experienced disruptions.

As of October 5, 2026, no data leak has been confirmed, and the investigation conducted with external experts and law enforcement remains ongoing. Unlike Times Car, Keio has not disclosed the ransomware strain, entry vector, or ransom demands.

Why Japan’s Transportation Sector Is a Prime Target

The incidents reflect a broader trend of ransomware and data breaches targeting Japan’s mobility and infrastructure firms. Key factors include:

  • High-value data: Car-sharing platforms accumulate identity documents required for rentals, making them lucrative targets.
  • Operational leverage: Even non-disruptive ransomware attacks on rail operators generate public pressure, increasing extortion incentives.
  • Legacy IT systems: Many transportation firms rely on older infrastructure, creating security gaps.

Impact and Next Steps

  • Times Car: Park24 faces regulatory scrutiny and potential customer trust erosion, particularly over identity-document handling. Affected users are advised to reset passwords and monitor for identity misuse.
  • Keio: While train services continued normally, the incident underscores the importance of network segmentation in limiting ransomware impact. Further updates are expected as the investigation progresses.

Both companies have emphasized that the incidents are unrelated, though their near-simultaneous disclosure has drawn attention to Japan’s growing cybersecurity challenges in critical infrastructure. Regulatory involvement and industry-wide audits are likely in the coming months.

Source: https://shattered.io/times-car-breach-6-6-million-keio-ransomware-2026/

Times Mobility TPRM report: https://www.rankiteo.com/company/traveltime-mobility-india-pvt-ltd

"id": "tra1791260682",
"linkid": "traveltime-mobility-india-pvt-ltd",
"type": "Breach",
"date": "10/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '6.6 million current and former '
                                              'users',
                        'industry': 'Transportation/Mobility',
                        'location': 'Japan',
                        'name': 'Times Car (Times Mobility, subsidiary of '
                                'Park24)',
                        'type': 'car-sharing platform'},
                       {'industry': 'Transportation/Railway',
                        'location': 'Japan',
                        'name': 'Keio Corporation',
                        'type': 'railway operator'}],
 'customer_advisories': 'Affected users advised to reset passwords and monitor '
                        'for identity misuse (Times Car)',
 'data_breach': {'file_types_exposed': ['Images (driver’s license)'],
                 'number_of_records_exposed': '6.6 million (Times Car)',
                 'personally_identifiable_information': 'Yes (Times Car)',
                 'sensitivity_of_data': 'High (identity-verification documents '
                                        'like driver’s license images)',
                 'type_of_data_compromised': ['Names',
                                              'Addresses',
                                              'Phone numbers',
                                              'Email addresses',
                                              'Dates of birth',
                                              'Membership numbers',
                                              'Driver’s license details',
                                              'Linked-service IDs',
                                              'Account passwords']},
 'date_publicly_disclosed': '2026-09-25',
 'description': 'In a 24-hour span in late September 2026, two major Japanese '
                'transportation entities Times Car, a car-sharing platform, '
                'and Keio Corporation, a leading railway operator confirmed '
                'separate cybersecurity incidents, exposing vulnerabilities in '
                'the country’s mobility sector.',
 'impact': {'brand_reputation_impact': 'Potential customer trust erosion '
                                       '(Times Car)',
            'data_compromised': '6.6 million accounts (Times Car), unknown '
                                '(Keio Corporation)',
            'identity_theft_risk': 'High (Times Car due to '
                                   'identity-verification documents)',
            'legal_liabilities': 'Regulatory scrutiny (Times Car)',
            'operational_impact': 'Railway operations remained unaffected '
                                  '(Keio Corporation); business systems '
                                  'experienced disruptions (Keio Corporation)',
            'systems_affected': ['back-office systems (Keio Corporation)',
                                 'sales and reservations at affiliated '
                                 'companies (Keio Corporation)']},
 'investigation_status': 'Ongoing (Keio Corporation)',
 'lessons_learned': 'The incidents highlight vulnerabilities in Japan’s '
                    'mobility sector, including high-value data accumulation, '
                    'operational leverage for ransomware, and legacy IT '
                    'systems.',
 'post_incident_analysis': {'root_causes': ['Legacy IT systems',
                                            'High-value data accumulation']},
 'ransomware': {'data_exfiltration': 'No data leak confirmed (as of October 5, '
                                     '2026)'},
 'recommendations': ['Reset passwords (Times Car users)',
                     'Monitor for identity misuse (Times Car users)',
                     'Enhance network segmentation (Keio Corporation)',
                     'Conduct industry-wide audits'],
 'references': [{'source': 'Cyber Incident Description'}],
 'response': {'containment_measures': 'Isolated affected network segments '
                                      '(Keio Corporation)',
              'law_enforcement_notified': 'Yes (Keio Corporation)',
              'network_segmentation': 'Yes (Keio Corporation)',
              'third_party_assistance': 'External experts (Keio Corporation)'},
 'title': 'Japan’s Transportation Sector Hit by Dual Cybersecurity Incidents '
          'in Late September 2026',
 'type': ['data_breach', 'ransomware']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.