About 6.6 million current and former accounts of Times Car, one of Japan's largest car-sharing services, were exposed in a cyberattack. For roughly 1.6 million of them, the data included images of identity documents such as driver's licenses, according to Nikkei xTECH and Hackread. The operator, Times Mobility of the Park24 group, detected the break-in on September 25.
A leaked password can be changed. A leaked copy of a driver's license cannot. "A copy of someone's identity document can remain useful to criminals long after the initial incident," says Michael Centrella of the security firm SecurityScorecard, quoted by Hackread.
What was taken
According to the company, the attackers reached names, addresses, dates of birth, phone numbers, email addresses and driver's license details. Passwords were stored in a form that cannot be turned back into the original, and credit card data was not affected. IDs for nine linked services were exposed too, and department names for corporate customers.
The 6.6 million figure counts accounts, not people, so one person can appear more than once.
The response
Times Mobility says it spotted the unauthorized access at 9:07 a.m. on September 25 and blocked the route by 7:25 a.m. the next day. How the attackers got in is still under investigation, with outside forensic experts.
The company reported the breach to Japan's data protection commission and the police and warned customers about phishing. It says there is no sign the data has been published or misused so far.