Data breaches have become so common that many people barely react when the leaked fields are just names and email addresses.
The September 2026 Times Car incident was different.
According to Park24’s September 28 report, an unauthorized party accessed the Times Car web system and obtained information associated with roughly 6.6 million accounts. The affected population included current members, former members, people who had applied but never completed enrollment, and business customers including former ones.
The exposed fields varied by person, but included names, addresses, dates of birth, phone numbers, email addresses, driver’s-license information, identity-document information and driver’s-license images.
This was much closer to an “identity bundle” than a simple contact list.
And that is where the most irritating part begins: the company investigates the incident, while users spend their own time cleaning up after it.
1. The contents matter more than the headline number
Six-point-six million accounts is large, but breach severity is not measured by volume alone.
An email address by itself mainly increases spam and phishing exposure.
A linked set of name, address, date of birth, phone number and identity documents gives an attacker a much richer profile of a real person.
Japan’s Personal Information Protection Commission distinguishes ordinary contact-data exposure from incidents that can enable impersonation and financial harm. The danger rises when the leaked data can be used to convincingly act as someone else.
That is why the Times Car case feels worse than “another mailing list leak.”
2. Former customers being included is especially frustrating
Former customers were also affected.
That does not automatically mean retaining their data was unlawful. Companies can have legitimate retention needs related to contracts, accounting, fraud prevention or disputes.
But from a user’s perspective, it is difficult to accept hearing, years after leaving a service, that identity documents associated with an old account were still within the affected system.
The meaningful governance question is simple: what is being retained, why, and for how long?
Data can be an asset. Once breached, unnecessary retained data becomes liability surface.
3. A leaked driver’s-license image does not automatically open a bank account
This needs precision.
Remote identity verification in Japan is not one uniform process. Depending on the service, verification can combine document images, real-time facial capture, chip data or public digital authentication.
So possession of a saved driver’s-license image does not mean someone can automatically open an account at every financial institution.
Japan is also tightening these rules. Financial regulators are moving away from higher-risk remote verification methods based on images of identity documents, with reforms scheduled for April 1, 2027.
Liveness checks and chip-based verification exist precisely to make static stolen images less useful.
4. The long-term problem is credibility for impersonation
A driver’s-license image alone is not a master key.
But an identity bundle makes scams more convincing. A caller who knows your name is one thing. A caller who knows your name, address, birth date, phone number and a service you once used is another.
Unlike a payment card number, many identity attributes cannot simply be replaced.
JICC, one of Japan’s credit information agencies, explicitly allows people whose identity-document images have leaked to register a comment intended to warn against misuse of their name. The registration can remain for five years.
That does not mean abuse is inevitable. It means the risk is real enough that defensive systems exist for it.
5. Card leaks and identity leaks are two different kinds of misery
Park24 says payment-card information was not leaked in this incident. That matters.
A card leak can create immediate financial risk, but cards can be stopped and reissued.
Then comes the cleanup: streaming services, online stores, mobile wallets, utilities, transport apps, cloud services and forgotten subscriptions all need the new number.
Identity data is different. It may be less immediately monetizable, but dates of birth, historical addresses and document details are much harder to replace.
Card leakage is often a short, intense cleanup. Identity leakage can become a long, quiet vigilance problem.
6. Breach “damage” should include the cleanup tax
Incident notices often say there is currently no confirmed financial loss.
That is useful information, but it is not the entire cost.
Users may still have to review passwords, watch suspicious messages, investigate credit-protection options, change payment details, read follow-up notices and stay alert months later.
That can consume hours or an entire day.
A breach can therefore impose real costs even when no money has yet been stolen: time, attention and uncertainty.
The company has an incident. The customer inherits unpaid security administration.
7. Is AI causing more cybercrime?
It is reasonable to ask whether today’s wave of incidents is related to AI.
There is no public evidence as of September 30, 2026 that AI caused the Times Car intrusion. The cause remains under investigation.
More broadly, however, government cyber assessments increasingly treat AI as a force multiplier.
The UK NCSC reported in 2025 that AI is already making parts of cyber operations more efficient, including reconnaissance, vulnerability research, social engineering, basic malware generation and processing stolen data. It expects AI to increase the frequency and impact of intrusions through 2027.
The key idea is not “AI becomes an autonomous super-hacker.”
It is human-machine teaming: people provide intent and expertise while AI reduces the cost of research, sorting, writing and repetitive work.
The NCSC still assessed fully automated end-to-end advanced attacks as unlikely by 2027.
8. Safety controls on mainstream AI do not eliminate the problem
Even if major AI services block obviously malicious requests, criminal capability does not depend on one model doing everything.
Existing knowledge, public information, stolen datasets, ordinary software, specialized tools and human judgment can be combined.
Europol’s 2025 IOCTA describes stolen data itself as a commodity that powers a wider criminal economy, including fraud, extortion and ransomware.
AI is best understood here not as an invention of new crime, but as something that can remove friction from crime that already exists.
9. “Breaches are everywhere” is statistically more complicated than it feels
The perception is understandable, but the incident count is not simply rising every year.
Tokyo Shoko Research reported 180 disclosed personal-data loss or breach incidents among listed Japanese companies and subsidiaries in 2025, down 4.7% from 189 in 2024.
Yet the number of people affected nearly doubled to about 30.64 million because six incidents exceeded one million people each.
Japan’s Personal Information Protection Commission also processed 17,139 private-sector breach reports in fiscal 2025, down from 19,056 the year before.
So the stronger trend is not necessarily “more incidents every year.” It is that a single incident can now affect millions of people and expose increasingly reusable data.
10. Conclusion: count the lost weekend too
The Times Car incident is not disturbing only because of the 6.6 million figure.
Former customers were included. Identity documents were involved. Many exposed attributes cannot be changed. And even without confirmed misuse, vigilance costs remain.
If a card leaks, users may lose a weekend replacing it everywhere.
If an identity bundle leaks, the cleanup can turn into a much longer background task.
For companies, this is incident response.
For users, it can become surprise unpaid security work.
When we calculate the real damage of a breach, we should count more than stolen money.
We should count the lost weekend too.
Sources
- Park24, Times Car unauthorized access second report, 2026-09-28
https://www.park24.co.jp/news/2026/09/20260928-1.html - Japan Personal Information Protection Commission, FY2025 Annual Report
https://www.ppc.go.jp/aboutus/report/annual_report_2025/ - PIPC FAQ on leaked contact data and financial harm
https://www.ppc.go.jp/all_faq_index/faq1-q6-11_/ - Japan Financial Services Agency materials on identity-verification reform
https://www.fsa.go.jp/common/ronten/202510/05.pdf - JICC, fraud-prevention declaration system
https://www.jicc.co.jp/comment/ - UK NCSC, Impact of AI on cyber threat from now to 2027
https://www.ncsc.gov.uk/report/impact-ai-cyber-threat-now-2027 - Europol, IOCTA 2025
https://www.europol.europa.eu/publication-events/main-reports/steal-deal-and-repeat-how-cybercriminals-trade-and-exploit-your-data - Tokyo Shoko Research, 2025 listed-company personal-data incidents
https://www.tsr-net.co.jp/data/detail/1202348_1527.html
