SOCLYDE logo
Current languageEN
Cybersecurity newsData breachSecurity incident

Times car: data from 6.6 million accounts exposed

Park24 confirmed data tied to 6.6 million Times Car accounts was taken, including identity document images for about 1.6 million.

By Soclyde Team

A person compares a car-share document with information on a phone

In summary

  • On September 28, Park24 confirmed a third party obtained data associated with about 6.6 million Times Car accounts.
  • Its September 29 report confirmed images of identity documents tied to about 1.6 million accounts were taken.
  • The accounts include former members and incomplete applications; Park24 says payment card data was not affected.

Explore next

Soclyde resources

Article contents

On September 25, 2026, Times Mobility reported unauthorised access to the web system for its Times Car car-sharing service. Its parent group Park24 confirmed on September 28 that a third party had obtained information associated with about 6.6 million accounts. The company blocked the detected access path on September 26 and continues its investigation with external specialists.

The figure counts accounts, not necessarily that many people. The scope includes current and former members, incomplete membership applications and accounts in the business service.

Categories of affected data

Park24’s notices say the data varies by account and may include names, addresses, dates of birth, phone numbers, email addresses, driver’s licence details, corporate data and IDs for partner services. Park24 says payment card information was not taken.

The company says passwords were stored in a non-recoverable form, but it has not detailed the method. This statement does not allow an independent assessment of weak or reused passwords; avoid claiming there is no risk.

About 1.6 million identity document images

In its third notice, dated September 29, Park24 confirmed identity document images were taken for about 1.6 million accounts. The list includes driver’s licences, proof of address, student IDs for some plans and family verification documents. The company began emailing affected members.

The notices do not specify exactly which documents were taken for each person. Park24 says it plans to provide individual details after the external investigation. Affected people should therefore rely on their direct notification rather than a general estimate.

Why former members are included

Park24 says the scope also includes former members and people who did not complete registration. The published notices do not detail every reason for retaining data or the contents of each account. Keep the number of affected accounts distinct from the number of people and documents actually retrieved.

Identity data that is difficult to replace can facilitate impersonation attempts. Park24 had not confirmed fraudulent use in its early communications, but advises people to watch for messages and calls impersonating Times Car.

Steps Park24 advises

Park24 advises people not to open links or attachments in unexpected communications claiming to be from the company, and not to enter a password, authentication code or card details in response. The company says it will not ask for this information by email, text or phone.

If you receive a direct notification, review the details specific to you and verify information by typing the Times Car address yourself. If the affected password was reused on other services, change it there too, starting with your email account.

The Soclyde connection

The Times Car incident concerns account data and identity documents; Soclyde does not protect the operator’s system. Soclyde is a local-first password and access manager; its encrypted vault helps users keep distinct credentials on their devices. It cannot remove copied data or replace the company’s notifications and response measures.

Takeaway

Park24 confirmed that a third party obtained information associated with about 6.6 million Times Car accounts, including document images for about 1.6 million accounts. The company says payment card data was not affected. People who receive a notice should follow Park24’s guidance and watch for impersonation attempts.

To reduce password reuse, read our guide to local-first password managers.

Frequently asked questions

What information was taken?

Park24’s notices say categories may include names, addresses, dates of birth, phone numbers, email addresses, licence details and some linked service IDs. Images of licences, proof of address, student IDs or family documents are confirmed for about 1.6 million accounts. The details vary by person.

Was payment card data exposed?

Park24 says payment card information was not taken. It also says passwords were stored in a non-recoverable form, without publishing the method used. Those details do not remove the risk from identity document images.

What does Times Car advise members to do?

Park24 advises members to watch for emails, texts and calls impersonating the company, avoid their links and attachments, and not share passwords, codes or card details. People who receive a notice should check the individual details sent directly by the company.

References

Sources and references

Need advice?

Design your password strategy with Soclyde

Schedule a dedicated walkthrough with the team to see how local-first security adapts to your stack.

Talk with us

Keep reading