Times Mobility, the operator of Times Car Rental and related services, disclosed a significant data breach last week affecting approximately 6.6 million accounts. The breach, detected last Friday morning, involved unauthorized access to personal information of both current and former members of Times Car and Times Business Service.

According to the company, the intrusion lasted until Saturday morning, when the access point was blocked. The compromised data includes names, home addresses, telephone numbers, and email addresses. While no credit card details were accessed, the breach notably involved the unauthorized retrieval of around 1.6 million personal documents used for identity verification. These documents included images of utility bills, student identification cards, and driver’s licenses, with the latter revealing personal photos.

PARK24, Times Mobility’s parent company, said on Monday that an external forensic specialist is investigating the incident to determine its cause and full scope. The company has also reported the breach to the Personal Information Protection Commission as well as law enforcement authorities.

Data security experts have noted that the exposure of personal photos, such as those on driver’s licenses, is relatively rare in data breaches and raises heightened concerns about potential identity theft or fraudulent activity. In the days following the disclosure, credit information agencies reportedly experienced a surge in inquiries, though no direct connection to the Times breach has been officially confirmed.

In response to the incident, Times Mobility has warned users to be vigilant against phishing attempts, including emails or phone calls impersonating the company. The firm emphasized that it will never request passwords or credit card information via such channels. Users are advised to secure their personal information and monitor accounts closely for any suspicious activity.