Japan's 6.6 Million Data Breach Is a Warning for Asian Mobility
Park24's Times Car breach exposed up to 6.6 million records, including 1.6 million driver's license photos. Victims must now pay out of pocket for fraud prevention — a system flaw Japan can no longer ignore.
Who Pays When 6.6 Million Records Leak
The phone line to Times Car’s dedicated hotline was jammed. A caller reached the automated prompt, heard “we are currently receiving many calls,” and eventually got cut off. When he finally connected with a representative, he was told the simple truth: his rental-car records were not part of the leak. Only Times Car subscribers were affected.
That distinction — between two services operated by the same parent company — felt like a detail buried under a much larger crisis. On September 25, Park24, the company behind the Times Car car-sharing network, disclosed that unauthorized external access had stolen personal data from up to 6.6 million users. Roughly 1.6 million of those records contained images of driver’s licenses and other identity documents. That is a quarter of a million more than the entire population of some mid-sized Japanese cities, all carrying photos of government-issued ID in the hands of unknown actors.
The timing is significant. Japan’s Act on the Protection of Personal Information (APPI) was revised in 2022 to introduce stricter rules on cross-border data transfers and to increase penalties for negligent breaches. But enforcement has been sporadic, and penalties remain modest by international standards. This breach is large enough to force a reckoning.
The Real Cost: Fees Shifted Onto Victims
What has drawn the sharpest criticism is not just the volume of leaked data, but the way Park24 and the credit-information ecosystem are handling the aftermath. Users who suspect fraudulent card applications in their name must file a fraud-prevention notice with credit bureaus such as CIC and JICC. The process is free in theory, but applicants must pay a handling fee — approximately 1,000 yen per bureau. For someone covering both, that is roughly 2,000 yen out of pocket.
One Times Car member, a three-year subscriber, told reporters he was “filled with anger” at having to pay for a safeguard that should have been guaranteed. “Why did the data leak in the first place? Where are the improvement measures? Where is the compensation?” Those are not rhetorical questions. They are the exact questions a legal system needs to answer before a breach becomes a precedent.
Japan does not have a U.S.-style class-action mechanism. But the 2023 establishment of a representative action system under the Civil Procedure Code — though still narrow in scope — opened a door. If a group of affected users were to band together and sue Park24 for negligence, the driver’s-license images would be the kind of damaging evidence no corporate defense team wants to see in open court. The fees charged to victims for fraud-prevention notices would be Exhibit A.
Why Driver’s License Photos Change Everything
Not all data breaches are equal. A leak of names and phone numbers is inconvenient. A leak of government-issued ID photos is dangerous. Driver’s licenses in Japan contain a photo, address, date of birth, and license number — enough information for identity fraud, fake-card applications, and social-engineering attacks that bypass basic verification checks.
Criminals known as tokuryu — anonymous, fluid cybercrime groups — have been active in Japan, and leaked identity documents are among the most valuable goods on underground markets. A driver’s license photo is portable, permanent, and hard to “change” the way you change a password. Once it is out there, the damage is structural.
Park24’s statement, posted on the Times Car website, offered a generic apology and promised to release more detailed findings “within about two weeks” based on an external investigation. Two weeks is a long time for 1.6 million people holding leaked ID images. It is also long enough for those images to circulate through multiple channels before any remediation framework is in place.
A Pattern Across Asian Mobility
This is not an isolated incident. Across Asia, mobility and ride-hailing platforms have grown faster than their data-protection infrastructure. Companies in Japan, Korea, and Southeast Asia routinely collect driver’s-license scans, vehicle registration data, and payment information — often with minimal encryption and weaker retention policies than financial institutions are required to maintain. The assumption has been that because these are “convenience” services rather than banks, regulatory scrutiny will be lighter.
Japan’s case is notable because the country has one of the more developed legal frameworks for personal-data protection in Asia, outside of South Korea’s strict PIPA regime. If a Japanese car-sharing company can leak 1.6 million ID photos and make victims pay for the privilege of protecting themselves, the message to regulators across the region is clear: current safeguards are insufficient, and the cost of non-compliance is being transferred from corporations to consumers.
What Happens Next
Park24 has not yet announced compensation terms. The external investigation is ongoing. Credit bureaus have reported surges in traffic, with application systems temporarily suspending new filings — a sign that the infrastructure designed to protect consumers buckled under the weight of a single breach.
The most likely outcome is a settlement quiet enough to avoid setting a broad legal precedent, paired with a public promise to upgrade security. That is the pattern Japan has followed before. But the scale of this breach — 6.6 million records, 1.6 million with ID photos, victims billed for fraud prevention — may be large enough to break the cycle.
For users across Asia who share personal data with mobility platforms as a routine part of daily life, the Times Car breach is a stark reminder: convenience without accountability creates vulnerability. And when the vulnerability becomes a leak, the bill for fixing it should not come from the people who trusted the service in the first place.