Find notable cyber news and cases, enriched with sources, timelines, and signals.

Times Car hit by network compromise

Incident
First reported
Last updated
Happening score
H score 59
1 unique sources, 1 articles

Summary

Hide ▲

Times Car confirmed a cyberattack that compromised about 6.6 million current and former member accounts, exposing personal and identity data across its car-sharing service. The intrusion involved unauthorized access to systems at the beginning of the month and was blocked on September 26. Exposed data included names, addresses, birth dates, phone numbers, email addresses, driver’s license information, account passwords, and linked service IDs. There is no evidence the stolen data has been published online, credit card information was unaffected, and services continue to operate normally.

Related Happenings

Times Car member and corporate account data leak

Data Leak
H score62 First: 28.09.2026 23:31 Last: 28.09.2026 23:31 Sources 1

How related: At the time, the company said it was investigating whether the attackers accessed members' personal information, but confirmed the data theft in an update earlier today.

About this happening: Times Car confirmed a data theft affecting approximately 6.6 million current and former member accounts, creating identity-theft and phishing risk for a large customer bas...

Timeline

  1. 28.09.2026 23:31 2 articles · 1h ago

    Times Car confirms 6.6 million user accounts were compromised

    Victim Impact Update

    Times Car confirmed that approximately 6.6 million current and former member accounts were compromised after a third party accessed its systems at the beginning of the month, and said the intrusion also affected current and former members of the Times Business Service corporate account program. The exposed information included full name, department name for corporate members, physical address, date of birth, telephone number, email address, driver’s license information, identity verification document images, account password, and linked service IDs. The company said credit card information remained unaffected, there is no evidence the stolen data has been distributed online, all services continue to operate normally, and affected customers will be notified individually in stages.

    Show sources