Skip to content

Security1 publisher2 min readPublished

Times Car confirms driver's license images were taken in breach of 6.6 million accounts

Times Car says an intruder took names, addresses, birth dates and driver's license images in a breach affecting 6.6 million member accounts. Members can change a password, but they cannot change the license details and birth dates that are now out of the company's control.

The Watch · Security desk

Illustration accompanying Times Car confirms driver's license images were taken in breach of 6.6 million accounts

What happened

  • Beyond current members, the breach reaches former members and current and former users of the Times Business Service corporate account program.
  • Times Car, operated by Times Mobility within the Park24 Group, claimed 4 million active members as of August 2026.
  • The company says its investigation confirmed that members' credit card information was not affected.
  • Times Car will notify affected customers individually and in stages while an external expert investigates the cause and scope.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure At least 2.6 million exposed accounts fall outside the active base, so people who stopped using Times Car carry the same identity risk as current drivers.
  • exposure Department names for Times Business Service members let a phisher aim messages at specific teams inside Times Car's corporate client companies.
  • decision Members who linked other services to their Times Car account now have to decide whether to treat those accounts as exposed, since the linked IDs went with the record.

The quickest use of this data is phishing that quotes members' real details back to them. Times Car's own advice points there. It told members to be wary of emails, SMS and phone calls claiming to come from the company, and not to open attachments or type in passwords or card details [15]. A phisher working from the stolen record would have each member's phone number, email address, home address and date of birth [6]. They would also have driver's license information and identity document data, such as license images [7].

Passwords were taken as well, along with linked service IDs [8]. Times Car said the passwords were stored in "a form that cannot be restored" [9]. BleepingComputer took that to mean encryption or hashing [9]. Anyone holding the key can recover encrypted values, so the company's wording points to a hash. The update does not name the algorithm, say whether the document images were in the same system as the passwords, or say how many accounts held an image [9][7].

By Times Car's account, a third party got into its systems at the beginning of September. The company announced the incident on September 25 [2]. It blocked the access on September 26 [3]. Access lasted roughly three weeks [2], and the block came a day after the public notice [3]. On September 25 the company was still investigating whether personal information had been reached. It confirmed the theft in a later update [4].

Everything public so far comes from Times Car. The company calls the intruder a third party [2] and says it has no evidence that the stolen data has been distributed online [11]. On that record this is a single incident with an unnamed intruder, and the evidence does not tie it to any wider campaign [2][11].

What to watch

  • Times Car naming its password hashing algorithm, or the number of accounts that held a license image.
  • A leak-site listing or group claim for the data; either would overturn the company's statement that it has no evidence of distribution.
  • The external forensic findings on how the third party got in and why access lasted until September 26.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories