On September 25, 2026, Times Mobility reported unauthorised access to the web system for its Times Car car-sharing service. Its parent group Park24 confirmed on September 28 that a third party had obtained information associated with about 6.6 million accounts. The company blocked the detected access path on September 26 and continues its investigation with external specialists.
The figure counts accounts, not necessarily that many people. The scope includes current and former members, incomplete membership applications and accounts in the business service.
Categories of affected data
Park24’s notices say the data varies by account and may include names, addresses, dates of birth, phone numbers, email addresses, driver’s licence details, corporate data and IDs for partner services. Park24 says payment card information was not taken.
The company says passwords were stored in a non-recoverable form, but it has not detailed the method. This statement does not allow an independent assessment of weak or reused passwords; avoid claiming there is no risk.
About 1.6 million identity document images
In its third notice, dated September 29, Park24 confirmed identity document images were taken for about 1.6 million accounts. The list includes driver’s licences, proof of address, student IDs for some plans and family verification documents. The company began emailing affected members.
The notices do not specify exactly which documents were taken for each person. Park24 says it plans to provide individual details after the external investigation. Affected people should therefore rely on their direct notification rather than a general estimate.
Why former members are included
Park24 says the scope also includes former members and people who did not complete registration. The published notices do not detail every reason for retaining data or the contents of each account. Keep the number of affected accounts distinct from the number of people and documents actually retrieved.
Identity data that is difficult to replace can facilitate impersonation attempts. Park24 had not confirmed fraudulent use in its early communications, but advises people to watch for messages and calls impersonating Times Car.
Steps Park24 advises
Park24 advises people not to open links or attachments in unexpected communications claiming to be from the company, and not to enter a password, authentication code or card details in response. The company says it will not ask for this information by email, text or phone.
If you receive a direct notification, review the details specific to you and verify information by typing the Times Car address yourself. If the affected password was reused on other services, change it there too, starting with your email account.
The Soclyde connection
The Times Car incident concerns account data and identity documents; Soclyde does not protect the operator’s system. Soclyde is a local-first password and access manager; its encrypted vault helps users keep distinct credentials on their devices. It cannot remove copied data or replace the company’s notifications and response measures.
Takeaway
Park24 confirmed that a third party obtained information associated with about 6.6 million Times Car accounts, including document images for about 1.6 million accounts. The company says payment card data was not affected. People who receive a notice should follow Park24’s guidance and watch for impersonation attempts.
To reduce password reuse, read our guide to local-first password managers.



