BlackTree Security · Infrastructure · Automation · AI

A Password Reset Cannot Take Back the Identity Data Stolen From Times Car

Changing a password does little for an identity document acquired by an intruder. That is the lasting concern in the Times Car breach. On 28 September, operator Times Mobility confirmed that a third party obtained information associated with about 6.6 million accounts. The fields vary by account and include identity-document information such as driving licence images. The company has not said how many accounts contained an image, and its account figure is not a count of unique people.

As of its 28 September notice, Times Mobility had not confirmed any public release of the data or misuse resulting from the incident. That qualification matters: acquisition is confirmed, while subsequent impersonation or fraud is not. The investigation remains open.

What changed between the two notices

Times Mobility’s first notice on 25 September warned that member information might have leaked after unauthorised access to the Times Car web system. Its 28 September update says the investigation established that a third party obtained some member information stored in the affected system.

The company says it detected the access at 09:07 Japan time on 25 September. By 07:25 the next day, it says it had blocked the access route and communications from the attack source, then confirmed that route could no longer be used. It reports no new unauthorised access during continued monitoring. Times Car services are continuing, while outside specialists investigate the cause and scope. The public notices do not identify the intruder or explain the technical entry method.

The roughly 6.6 million affected accounts span current and former Times Car members, people whose applications were not completed, and current and former Times Business Service members. The notice gives no deduplicated headcount, so the account total should not be restated as a number of people.

The document category needs its own count

The company lists names, corporate members’ department names, addresses, dates of birth, phone numbers, email addresses, driving-licence information, identity-document information including driving licence images, passwords and linked-service IDs. It explicitly says the information varies by person. The published total therefore does not mean that every account included a licence image, a password record and every other listed field.

Times Mobility says credit-card information was not leaked. It also says passwords were stored in a form that cannot be recovered and that it has not confirmed exposure of passwords in a readable form. The notice gives no technical parameters for that storage, so this article cannot independently assess the account-safety conclusion the company draws from it. Neither the reported card exclusion nor the password statement resolves the separate question of what can be done with acquired identity documents.

Analysis: A driving licence image can remain useful as identity evidence long after a service password is changed. Combined with a real name, birth date or contact details, it could make a later impersonation attempt more convincing. This is a risk model, not a finding that any Times Car record has been used for fraud. Our separate analysis of identity-document disclosure in the Revolut incident explains why possession of authentic personal details should not, by itself, establish that a caller or applicant is legitimate.

Affected members need a trusted contact route

Times Mobility says it is contacting affected people individually in sequence. It warns against messages, texts or calls impersonating the company and says it will not ask for passwords or credit-card details through those channels. Anyone checking a notice should go directly to the official Times Car incident page rather than follow a link supplied in an unexpected message. The page lists the company’s enquiry routes.

Analysis: A message containing accurate account or licence details can still be fraudulent. An affected person can ask the company which data categories applied to their account, because the public notice provides only a combined list. Do not send a fresh identity-document image or a one-time code in response to unsolicited contact. Organisations that use document checks for account recovery should avoid treating static document details alone as proof of identity. Times Mobility’s next useful disclosure would distinguish accounts from unique people and specify how many acquired records contained document images, once its investigation can establish those figures.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *