Japan’s Wave of Data Breaches: What Is at Risk and How to Prepare, from Times Car and Yakiniku King to Gyazo (With Japanese Reactions)

Times Car, Yakiniku King and Gyazo disclosed major breaches within weeks. What leaked, why card safety is not the whole story, how to prepare, and Japanese Reactions.

Key Points

ใƒปBetween late September and early October 2026, several everyday services in Japan disclosed member data breaches. Times Car, Yakiniku King and Gyazo, the three covered here, each say credit card data was not part of what leaked.

ใƒปWhat leaked is mostly names and contact details, but Times Car also lost images of identity documents such as driver’s licenses, and Gyazo’s data included records of deleted images. Dates of birth and face photos cannot be taken back once they are out.

ใƒปThe way in differs by incident, so no single measure closes every door. Names and contact details can also become raw material for fraud once combined with other data, which leaves companies with the job of managing data from collection to deletion and users with preparation matched to what leaked.


Three Japanese Services Disclose Member Data Breaches in Weeks

Since September 2026, breaches of member data have been disclosed one after another at services people use every day. This article covers three Japanese cases and three from abroad.

According to Times Car’s September 28 announcement, the car-sharing operator, part of the Park24 group, detected unauthorized access on September 25 and found that account information for about 6.6 million accounts had leaked. The count includes current members, former members who had withdrawn, and people who started to sign up but never completed enrollment. The data includes names, addresses, dates of birth, phone numbers, email addresses and driver’s license information. In a September 29 follow-up, Times Car said images of driver’s licenses and address-verification documents had leaked for about 1.6 million accounts.

Times Car says passwords were stored in a form that cannot be restored, and that credit card data was not affected because it does not hold card data.

On October 5, Monogatari Corporation, which runs the Yakiniku King barbecue chain, announced that member information for about 10.79 million of about 10.81 million registered members had leaked from the member-management system of its official app. According to the company’s announcement, the data covers member numbers, registered app names, email addresses and phone numbers, and does not include passwords, dates of birth or usage history. The company says it does not hold payment data itself. The cause is under investigation, and the company says it is proceeding with a report to the Personal Information Protection Commission and a criminal complaint to the police.

On September 16, Helpfeel, which runs the screenshot-sharing service Gyazo, announced that about 23.62 million user records and about 490 million records about images had leaked. According to the company, the user data includes email addresses, password hashes (values converted into a form that cannot be reversed) and tokens used for X integration, and the image records include location data and text found inside images. About 76% of the user records belong to anonymous users who never registered an email address, so email addresses were not part of every record.

In a September 25 second report, Helpfeel said records of about 174 million deleted images were also affected. The image files themselves did not leak and the integration credentials were invalidated. The company asked all users to change their passwords and reopened the service on September 27. It says payment data was not included and that no secondary harm has been confirmed.

Similar large breaches were disclosed abroad in the same period. Denmark’s Ministry of Research, Education and Digitalisation said on October 5 that the names and addresses of about 8.8 million people, tied to their civil registration (CPR) numbers, had been accessed through the misuse of legitimate query access granted to a private company. Records of the deceased and of people who had moved abroad are included.

The U.S. Defense Department’s Defense Manpower Data Center (DMDC) is reported to have lost Social Security numbers and other data of about 3 million current and former service members through a vulnerability in a file-sharing system. The Arizona court system is reported to have had records of more than 1.3 million people, including people in a debt-collection program, potentially exposed through a phishing intrusion.


Related Articles


What Leaked, and What Was Still Being Stored

A “honnin shinkoku” (self-declaration) is a system run by Japan’s credit bureaus that lets a person register that their identity documents may have been compromised, so that lenders are prompted to take extra care when screening credit applications. It comes up below because the Times Car breach exposed driver’s license images.

Why companies say card data is not involved

All three companies say credit card data was not part of the leak. In Japan, card numbers are increasingly held by a payment processor and not kept on the service’s own systems. The credit industry’s security guideline asks merchants either not to hold card data or, if they do, to follow an international security standard.

A card number can be stopped and reissued if misused. Even when card data is not involved, information that cannot be taken back after a leak, such as dates of birth and face photos, can remain.

How the three cases compare

The contents of a leak differ by incident. Based on each company’s announcements and, where noted, press reports, the three compare as follows as of October 7, 2026.

Times CarYakiniku KingGyazo
Names and contact detailsYesYesYes (email of registered users)
Date of birth and addressYesNoNo
PasswordsStored in a form that cannot be restoredNoPassword hashes
Identity document imagesYesNoNo
Location data and image recordsNoNoYes
Former members or deleted dataYesNot statedYes

What could happen to you, and what to do about it, depends on which kind of member you were.

Records kept after members left

The Times Car breach included information on people who had already withdrawn. According to the company’s FAQ, names, addresses and dates of birth are kept for seven years after withdrawal under tax law and similar rules, and driver’s license information and images are also kept for seven years to prevent impersonation and handle inquiries. Gyazo’s affected data likewise included records of deleted images.

Under Japan’s Act on the Protection of Personal Information, deleting personal data that is no longer needed is only an obligation to make an effort, and where other laws require retention, those laws take priority. The same act requires safeguards for the data and, for certain kinds of leaks, a report to the authorities and notice to the individuals affected. The need to keep a transaction record and the need to keep a license image for years can be considered separately.


What Can Happen to You, and How to Prepare

Why do breaches keep happening across such different services?

The way in differs across the six cases. In the Gyazo case, a weakness in the system was the entry point. For the Pentagon agency, the reported entry point was a file-sharing system. In Denmark it was the misuse of legitimate query access, and in Arizona it was reported to be a phishing link opened by an employee. Times Car and Yakiniku King are still under investigation. A different entry point calls for a different fix, so no single measure stops all of them.

The attackers’ tools are changing too. In a report published on February 13, 2026, Google’s Threat Intelligence Group said state-backed groups had used generative AI to write lures tailored to their targets, to translate, and to help produce attack code. Anthropic’s September 2026 threat intelligence report describes a case in which humans set the targets while an AI agent carried out several stages of an intrusion, from reconnaissance and building phishing infrastructure to processing hundreds of gigabytes of stolen data.

When an attack takes less effort, more targets become worth attacking. Defenders, meanwhile, have to keep protecting everything, including old systems and the records of former members, and that gap is part of why breaches keep coming. Whether AI was used in the six cases covered here has not been confirmed.

So managing data is not only about keeping intruders out. What a company collects, who can see it, where it is handed over to and when it is deleted each set the ceiling on what could leak if someone gets in. How much is actually taken also depends on how the data is protected, such as how it is separated and encrypted.

Companies also have reasons to keep data. Times Car describes its license image storage as being for impersonation prevention and inquiry handling, and deleting records too aggressively makes it harder to examine disputes or stop banned users from re-registering. According to a Nikkei report on October 6, 2026, a rival operator, ORIX Auto, deletes license images soon after screening new members. There is room in each company’s design to separate looking at a document once to verify identity from holding it for years.

What can happen when the card is safe?

The risk grows when leaked data is combined with other data. An email address or phone number alone can be a target for scams, and a name, address and date of birth together can be matched against other leaks and public information to build an accurate profile of a person. A face photo on a license adds material for impersonation using identity documents. Gyazo’s location data and text records, as reported, could give clues about a person’s movements and private content.

A less obvious danger is contact from someone who knows real member details. A caller or sender who correctly names the service you used and the phone number or email you registered looks like the real company. Leaked data stays usable for years, so such contact can arrive later.

Helpfeel says it has confirmed no secondary harm, and the Pentagon’s notification is reported to say there is no sign of misuse. Companies warn of suspicious emails and text messages and of contacts that try to extract passwords or card data, and Times Car also asks users to watch for scams that impersonate the police. The Danish government likewise urged people not to give out passwords by phone or email even when the other party knows their name and address.

What to do depends on what leaked

The steps change with the type of data involved.

Where the data is mainly contact details, as with Yakiniku King, the practical step is to change how you treat messages. Even when the sender knows your membership details, check through the official app or website and not through the link you received. If you have entered information into a fake message, consult the service’s help desk and the police, as the National Police Agency advises, and change the password on every service that shares the same ID and password.

Where password hashes are involved, as with Gyazo, change the password as the company requests, and change it on any other service where you used the same one. A hash is hard to reverse, but simple passwords can sometimes be guessed. The Information-technology Promotion Agency (IPA) advises long, complex passwords that are not reused, along with multi-factor authentication or passkeys.

Where driver’s license images are involved, as with Times Car, one option is a honnin shinkoku with the credit bureaus. CIC, JICC and the Japanese Bankers Association’s personal credit information center each let people whose identity-document information leaked register, and the entry prompts lenders to take care when screening loans and credit. It does not automatically block contracts, and each lender decides how to screen. On license reissuance, the Chugoku Shimbun reported on October 6, 2026 that the Hiroshima Prefectural Public Safety Commission set up a special measure for people who want a new license, and practice differs by prefecture.

And some of it individuals cannot prevent. A leaked date of birth or face photo cannot be recovered, and documents that were mandatory to submit were not something users could choose to hand over less of. People who have withdrawn may not receive a notice, and Times Car has set up a dedicated form for checking whether you are affected. For companies, reviewing how long data is truly needed and how it is stored is their responsibility.


Japanese Reactions to the Times Car and Yakiniku King Data Breaches

This section collects posts on X by Japanese news outlets and reporters. The posts are reactions on X, not a measure of Japanese public opinion. The summaries are Sekahan’s English rendering of the gist of each post, not word-for-word translations. Engagement figures are omitted because they have not been rechecked.

Reaction to the breaches was mostly alarm from affected members, and the sharpest criticism centered on how long Times Car kept license images after members left. A report by the Nikkei, the Japanese business daily, put that detail in front of readers.

In summary, the Nikkei reported that license images were kept for seven years even after withdrawal. Park24 explained this as its own policy to prevent people from re-enrolling with forged licenses, while a rival rental-car company, ORIX Auto, was reported to delete such images soon after screening.

A Nikkei reporter added his own view in a follow-up post.

In summary, the reporter, Tatsuya Sudo, wrote that what makes the damage from unauthorized access larger is holding on to information that is no longer needed, and pointed readers to the report above.

The other thread concerned what to do about leaked license images. The Chugoku Shimbun, a regional newspaper, reported a measure in Hiroshima Prefecture.

In summary, the newspaper reported that the Hiroshima Prefectural Public Safety Commission would reissue driver’s licenses as a special measure for people who want one after the image leak. It was the most widely shared post we found on the topic. Practice may differ by prefecture, and this article does not present reissuing as a standard remedy.

Beyond these, posts we reviewed from individual users ranged from users saying they changed reused passwords, to questions over whether license images needed to be stored at all, to weariness that defenses such as password changes cannot stop a breach on the company’s side. The Gyazo breach drew little personal reaction in what we found, and mostly appeared in lists of large cases. Because many individual posts came from small accounts, we do not quote them.


What Cannot Be Recovered, and What Can Change

Three answers

Breaches continue because the entry point differs by incident and no single measure can close every one. How dangerous a leak is depends less on whether the card is safe than on what unrecoverable information gets combined with.

There are three things users can do. They can check contact from a party that seems to know them through an official channel, avoid reusing passwords, and, if identity documents leaked, consider a honnin shinkoku with the credit bureaus. Whether more companies show in a visible way what they hold and when they delete it depends on how each company designs its systems from here.


Frequently Asked Questions

Is credit card information included in the Times Car, Yakiniku King and Gyazo breaches?

No, according to the companies’ own announcements. Times Car says it does not hold card data and Yakiniku King’s operator says it does not hold payment data itself, while Gyazo’s operator says payment data was not included. Information that cannot be reissued, such as dates of birth and license images, can still be at stake.

How many people were affected by the Times Car and Yakiniku King breaches?

According to Times Car’s September 28 announcement, about 6.6 million accounts leaked, and its September 29 follow-up said license and address-verification document images leaked for about 1.6 million accounts. According to Monogatari Corporation’s October 5 announcement, about 10.79 million of about 10.81 million registered members’ information leaked from the Yakiniku King app.

What is a honnin shinkoku and does it protect me?

A honnin shinkoku (self-declaration) is a registration with Japanese credit bureaus such as CIC, JICC and the Japanese Bankers Association’s center, available to people whose identity-document information leaked, which prompts lenders to take care in screening. It does not automatically block contracts, and each lender decides how to screen.

Should I get my driver’s license reissued after a leak of license images?

Not as a standard step. The Chugoku Shimbun reported on October 6, 2026 that the Hiroshima Prefectural Public Safety Commission was offering a special reissue to people who want one, but practice differs by prefecture, so the police or public safety commission where you live is the place to ask.

How did Japanese social media react to the Times Car and Yakiniku King data breaches?

Among the posts we confirmed, news outlets and a reporter drew attention to Times Car keeping license images for seven years after withdrawal, and a regional newspaper reported a special license reissue in Hiroshima Prefecture. These are posts on X, not a survey of Japanese opinion.

Sekahan on YouTube

We publish video summaries of articles like this one, along with short clips built around Japanese reactions.


Reference Links

ใ“ใฎใ‚จใƒณใƒˆใƒชใƒผใ‚’ใฏใฆใชใƒ–ใƒƒใ‚ฏใƒžใƒผใ‚ฏใซ่ฟฝๅŠ 
Sekahan
Sekahan

Editor of Sekahan, a Japanese news-analysis blog. Writes English explainers built on Japanese-language primary sources such as Teikoku Databank reports, government white papers, and official statistics.

Articles: 626

Leave a Reply

Your email address will not be published. Required fields are marked *

CAPTCHA