Two separate security incidents in Japan reached the news at the same time. The Times Car data breach, 6.6 million accounts in total, hit the car-sharing and rental service. Separately, Keio Corporation confirmed a ransomware attack. The two are not the same event, but together they give affected customers a clear reason to review their account security today.

What was exposed in the Times Car data breach (6.6 million accounts)

Times Car has confirmed that roughly 6.6 million user accounts were compromised. Coverage of the disclosure describes a cyberattack that the company announced late in the previous week.

The details vary between reports, so treat them as reported rather than final. Several outlets say the exposed information includes names, addresses, birth dates, phone numbers and email addresses. One report says the exposure includes 1.6 million driver's license images. Another says the intrusion into the web system took place after September 25 and that payment card data was not leaked. The same report says the attacker has not been identified.

Two points matter most for readers:

  • Identity documents are different from passwords. A password can be changed in a minute. A license image and a birth date cannot be changed, so they stay useful to scammers for years.
  • Card data was reportedly not leaked. That is good news, but it does not make the rest of the exposed data harmless. Contact details plus personal information are what phishing and impersonation attempts rely on.

The reports we reviewed do not say that passwords were stolen. If that changes in the company's own notices, the advice below becomes more urgent.

Keio ransomware attack: a separate incident, not the same breach

Keio Corporation confirmed a ransomware attack in Japan. Based on the reporting available, this is an independent incident, and nothing indicates it is connected to the Times Car breach. Readers should not assume that a Keio customer is automatically a Times Car victim, or the reverse.

The two events do differ in kind. The Times Car case is a consumer-data exposure, where the main concern is what happens to customers' personal details. Ransomware typically aims to disrupt a company's systems and pressure it into paying. The reporting we have does not detail what data, if any, was taken in the Keio attack, so we will not guess. Keio customers should watch for official updates from the company.

If you want background on how ransomware crews operate, our coverage of the D1R ransomware attack on ARM shows how these groups can get around protections many people trust.

What affected users should do now

You do not need to panic, but you should act. The immediate personal risk is credential exposure and the way stolen contact details get reused in follow-up attacks. A practical checklist:

  1. Change your Times Car password. Do it even if the company has not said passwords were taken. Use a long, unique one.
  2. Replace any reused passwords. If you used the same password on email, shopping or banking accounts, change those too. Attackers routinely try leaked logins on other services.
  3. Turn on multi-factor authentication wherever it is offered, starting with your email account, since it can be used to reset everything else.
  4. Use a password manager so that every account can have a different password without you having to memorize them.
  5. Be skeptical of messages about your account or rental history. With names, phone numbers and emails reportedly exposed, scam emails and texts can look convincing. Do not click links in unexpected messages. Open the official app or type the website address yourself.
  6. Watch for identity misuse. If you uploaded a driver's license, keep an eye on unexpected account sign-ups, verification requests or contact from services you do not recognize.

Follow any instructions in the notice sent by Times Car. If you are unsure whether a message is genuine, contact the company through its official channels rather than replying to the message.

Why Japanese corporations keep getting targeted

The source reporting does not explain why these two incidents landed together, and it would be wrong to claim a single cause. What we can say is that they show two different threats operating at the same moment: a large consumer data exposure and a ransomware attack on a corporation. Both organizations hold the sort of data and operational systems that attackers find valuable.

The practical lesson is that you cannot control how a company protects its servers. You can control how much damage a leak does to you. Unique passwords limit how far one stolen login can travel. Multi-factor authentication adds a barrier. Careful handling of unexpected messages blunts phishing that uses real personal details.

Keep in mind that multi-factor authentication is not a complete defense. As the ARM case shows, determined attackers can find ways around it, so it works best alongside unique passwords and caution with links and attachments.

What This Means For You

If you have ever created a Times Car account, assume your details may be among the 6.6 million and act accordingly. If you are a Keio customer, you do not need to assume your data was part of the Times Car incident, but you should follow the company's updates on its ransomware attack.

For everyone else, these events are a reminder that your exposure depends on the weakest company holding your data. A few minutes spent on your passwords and sign-in settings is the most useful response available.

Key takeaways

  • Reset any password you reused, starting with your Times Car login and your email account.
  • Enable multi-factor authentication on important accounts, and remember it is one layer, not a guarantee. The D1R and ARM ransomware report explains why.
  • Treat unexpected emails and texts about your account as suspect, since personal details tied to the Times Car data breach, 6.6 million accounts in all, can make scams look real.
  • Wait for official notices on the Keio ransomware incident before drawing conclusions about your own data.