Personal data from 6.6 million car-sharing accounts exposed

Personal data from 6.6 million car-sharing accounts exposed. Personal data tied to approximately 6.6 million current and former Times Car members was compromised in a cyberattack.

This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Tuesday, September 29th, 2026.

Personal data tied to approximately 6.6 million current and former Times Car members was compromised in a cyberattack. The affected population also includes current and former members of the company’s corporate account program. Passwords were stored in what the company described as a form that cannot be restored, and credit card information was not affected. There was no evidence the stolen data had been distributed online, and the company’s services continued operating normally.

The immediate concern is follow-on fraud. Affected customers may receive convincing emails, text messages, or phone calls that appear to come from Times Car. Uninterrupted service is positive, but it doesn’t reduce the need for clear notification and customer support. Defenders should monitor for impersonation campaigns, investigate the original access path, and watch for reuse of exposed account details. Corporate program members may also receive lures built around their workplace relationship. Breach harm can continue even when business operations never stop. Notify affected members promptly and monitor for impersonation campaigns that use Times Car or corporate account details.

For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.

Personal data from 6.6 million car-sharing accounts exposed
Broadcast by