Skip to content
>_ITDITDWeb Security Platform

Security Guides

The outage ends, the leak answer comes later — what Cariteco (Meitetsu Kyosho) members should do after the ransomware attack

Ransomware hit Meitetsu Kyosho's servers, and driver's license data of current and former members of its car-sharing service Cariteco may have leaked, with card data for some members. Based on the company's notices: what members should do today.

Published 2026-09-30 Updated 2026-09-30 Last verified 2026-09-30 14 min read

For: current and former users of Meitetsu Kyosho's car-sharing service Cariteco in Japan, and staff at companies with corporate Cariteco contracts. This article is based on Meitetsu Kyosho Co., Ltd.'s official notices and does not cover attack techniques.

What members should do today

1

Check whether you are affected — former members count, and the letter may not have reached you

Affected people are current and former Cariteco members. The company sent individual notices by post or similar means to individual members on July 10 and 23 and to corporate members on August 20. But some could not be delivered, for example because of outdated addresses, so it also posted the notice online. If you moved after joining or left years ago, you may not have received one. If in doubt, call the Meitetsu Kyosho customer desk (personal-information line) at 0120-353-276 (weekdays 9:00–17:00, Japan).

2

Do not respond to calls, emails or letters claiming to be the company or a card issuer

The data in scope combines name, address, phone number and email address, which is enough to write convincing messages — including paper letters. The company asks members to be wary of suspicious calls, emails and mail, and not to readily comply with requests to enter or give personal information, authentication details or card information. If you need to check something, contact an official number you looked up yourself (see What is phishing?).

3

If you registered a card, check your statements

The company says card information may be included for some members, without saying which members or which items. If you registered (or may have registered) a card with Cariteco, check your statements for charges you do not recognize, and call the number on the back of the card if you find any. If you remain worried, you can explain the situation to your issuer and ask about replacing the number.

4

Register a fraud alert (self-declaration) with Japan's three credit bureaus

This is available when your name may be misused because an identity document was lost, stolen or leaked. Once registered, lenders and card issuers see the note when checking your file and review applications more carefully. CIC, JICC and the Japanese Bankers Association's credit information center have different member companies, so register with all three. Differences between the bureaus and how long alerts last are covered in the Times Car article.

5

Request your credit file and look for accounts you did not open

A fraud alert does not block applications. Request your own credit file from each bureau — once now and again a few months later — and look for cards or loans you never applied for. If an unfamiliar contract or collection notice arrives, contact that business and your local police station.

6

If you are a former member, ask for your data to be deleted

Japan's privacy law lets you request that a business stop using or delete your data when a reportable leak has occurred or when the business no longer needs the data (Article 35, paragraph 5). Former members can ask the desk whether their application-form data is still held and whether it can be deleted. Some records may have to be kept by law, but getting an answer on what remains and until when is worth it on its own.

7

Corporate account staff: warn colleagues about 'our bank account has changed' messages

Per the September 3 notice, corporate customers' company name, address, contact details, representative's information and bank account information, plus the license information of employees registered to use Cariteco, are in scope. Circulate a rule that emails or letters claiming "our payment account has changed" are verified through another channel, such as a phone call. Tell registered employees about the fraud-alert option too.

What happened (from Meitetsu Kyosho's notices)

Everything below is as stated in the official notices of the company and of Cariteco.

  1. Jun 23, 2026

    The company detected suspicious access to its servers. Some servers stopped, and it immediately isolated systems and cut network connections.
  2. Jun 29

    Cariteco announced that, because of the outage, new sign-ups and changes to existing members' names, addresses and phone numbers, as well as new corporate sign-ups, were suspended.
  3. Jul 2

    The company disclosed the outage caused by unauthorized access. It said the outside investigation had "confirmed traces of unauthorized access by ransomware on June 19". At that point no leak of information outside the company had been confirmed; the police and relevant authorities were consulted and informed.
  4. Jul 6

    A customer call center was opened.
  5. Jul 10 and 23

    Individual notices about a possible leak were sent to individual Cariteco members.
  6. Jul 22

    Cariteco resumed new sign-ups and contract-change procedures.
  7. Jul 28

    The company said the investigation had found attacks on multiple servers and that it could not rule out a leak of customer information.
  8. Aug 4

    Cariteco posted a notice on its site about the possible leak of member information, explaining that some individual notices could not be delivered and the post was meant to cover them.
  9. Aug 20

    Individual notices were sent to corporate Cariteco customers (also posted online on September 3).
35 days
From detecting the outage (Jun 23) to announcing a possible leak (Jul 28)
~1 month
Cariteco new sign-ups suspended (Jun 29 notice to Jul 22 restart)
Not disclosed
Number of people affected
Former members too
Includes members who already left
Data that may have leaked (from Meitetsu Kyosho and Cariteco notices)
Individual members
What was written on the application form: name, address, date of birth, phone number, email address, driver's license information
Card data
May be included for some members (which members and which items not disclosed)
Corporate customers
Company name, address, contact details, representative's information, bank account information provided when the relationship began, and the license information of employees registered to use Cariteco
Scope
Current and former members. No count disclosed
Stated cause
Unauthorized access by ransomware; attacks on multiple servers confirmed. Entry route and other details not disclosed
Secondary harm
The company says no leak or misuse of personal information has been confirmed
Other services
Besides Cariteco, the company has sent individual notices to users of several other services, such as monthly parking customers and point-card members
Contact
Meitetsu Kyosho customer desk (personal-information line) 0120-353-276 (weekdays 9:00–17:00, Japan)

How to read it: what 'driver's license information' means is not stated

In the Times Car case, the operator explicitly said driver's license images were included. Cariteco's notice says only "driver's license information", so it is unclear whether that means the details printed on the license, such as number and expiry date, or also images. Either way, a license number combined with your name, address and date of birth cannot be changed, so the steps in this article are the same. We will update if details are published.

What is specific to this case: with ransomware, "fixed" and "leaked?" arrive separately

Jun 23 outage

Servers stopped and isolated; sign-ups suspended

↓

Jul 2 disclosure

Ransomware traces; leak "not confirmed"

↓

Jul 22 restart

Cariteco sign-ups and changes

From Jul 28: "cannot rule out a leak" / individual notices (some undeliverable)

→ "The service is back" does not mean "the data was safe". Members' precautions start at this stage

The sequence of Meitetsu Kyosho's notices. Service recovery and the finding of a possible leak came at different times.

A ransomware attack first shows up as "it doesn't work": bookings fail, sign-ups stop, sites go down. That is what users learn first. Whether data was taken only becomes clear after the stopped servers are examined one by one. In Meitetsu Kyosho's case, on July 2 the company said "no leak of information outside the company has been confirmed", and it was on July 28 — after Cariteco had resumed sign-ups — that it said a leak could not be ruled out.

The lesson for users: when an outage notice appears, recall what you have entrusted to that service. Services you have left are especially risky, because your contact details there may be out of date and the later leak notice may never reach you. How ransomware works and how organizations prepare are covered in What is ransomware?.

The two car-sharing cases side by side

In 2026, two car-sharing cases involving driver's license data were disclosed in Japan. Laid side by side, what members should do is the same; the differences are in certainty and how people were notified.

ItemTimes CarCariteco (Meitetsu Kyosho)
Starting pointUnauthorized access to the websiteSystem outage from ransomware
CertaintyConfirmed obtained by a third partyCannot rule out a leak
Count~6.6M accounts (~1.6M with ID-document images)Not disclosed
LicenseIncludes images"Driver's license information" (images not specified)
Card dataConfirmed not leakedMay be included for some members
Former membersIncludedIncluded
Individual noticeEmailPost or similar (some undeliverable)

For car-sharing operators: separate "needed for screening" from "kept forever"

The company has not said why it kept former members' application data. A car-sharing service has business reasons of its own, such as confirming a valid license for each rental. With that said, here is what operators can review based on what the two cases have in common.

1

Set a deletion deadline for former members' application data

Checking a license at sign-up is necessary. But former members' application data is not used by the business, yet it is still in scope when a leak happens. Japan's privacy law asks businesses to make efforts to delete personal data without delay once it is no longer needed (Article 22, a duty of effort). Keep it for the legally required period if there is one, otherwise set a short deadline, and make it delete automatically when the deadline passes.

2

If you cannot delete it, keep it reachable — check how current contact details are

The company says some individual notices could not be delivered. For any service that keeps member data for years, it is common for the contact details to go stale while the rest of the record stays. This site's view, for operators in general: ID data for people you can no longer reach, and have no duty to keep, is data whose retention should be reviewed. For data you must keep, prompt people to update their contact details; data where you cannot reach the person and have no duty to keep it, delete. Decide both in the same inventory.

3

Be able to restore when stopped, and limit harm if data is taken

Ransomware preparation has two parts: being able to restore from backups, and separating servers that hold customer data from the general business network. The first is covered in Backup essentials (the 3-2-1 rule), and the organization-wide minimum in The minimum security baseline for organizations.

Sources (public record)

The facts in this article come from the public sources below. Undisclosed intrusion routes or methods are not speculated on.

  • Meitetsu Kyosho Co., Ltd., notice on the system outage caused by unauthorized access (July 2, 2026, Japanese) — mkyosho.co.jp
  • Meitetsu Kyosho Co., Ltd., opening of a customer call center for the outage (July 6, 2026, Japanese) — mkyosho.co.jp
  • Meitetsu Kyosho Co., Ltd., notice on a possible customer data leak from the unauthorized access (July 28, 2026, Japanese) — mkyosho.co.jp
  • Meitetsu Kyosho Co., Ltd., status of individual notices about a possible leak (as of August 6, August 12 and September 3, Japanese) — Aug 6 / Aug 12 / Sep 3
  • Cariteco, apology and notice on a possible personal-data leak from unauthorized access (August 4, 2026: individual members, Japanese) — cariteco.com / same (September 3, 2026: corporate customers) — cariteco.com
  • Cariteco, system outage notice (June 29) and restart of sign-ups and applications after recovery (July 22, Japanese) — Jun 29 / Jul 22
  • Credit-bureau self-declaration (Japanese): CIC / JICC / Japanese Bankers Association credit information center
  • Act on the Protection of Personal Information, Articles 22 and 35 (Japanese) — e-Gov Law Search
  • Times Car figures are from Times Mobility Co., Ltd.'s notices of September 28 and 29, 2026 (details and sources in the Times Car article)

Update history

2026-09-30: First version, based on Meitetsu Kyosho's notices from July 2 to September 3 and Cariteco's notices of August 4 and September 3. The company says it will announce new facts, including whether a leak occurred; this article will be updated when it does.

FAQ

QWhat happened at Cariteco?
A

According to operator Meitetsu Kyosho Co., Ltd., it detected suspicious access to its servers on June 23, 2026; some servers stopped, and it immediately isolated systems and cut network connections. An investigation with outside specialists found traces of unauthorized access by ransomware (disclosed July 2). On August 4 it announced that, as the investigation continued, it could not rule out that Cariteco member information had leaked.

QWhat data may have leaked?
A

Per the August 4 notice: the information written on the membership application form — name, address, date of birth, phone number, email address and driver's license information. For some members, credit card information may also be included. For corporate customers, a September 3 notice lists the company name, address, contact details, representative's information and bank account information provided when the business relationship began, plus the license information of employees registered to use Cariteco. No count has been disclosed.

QAm I affected?
A

The company says both current and former Cariteco members are included. Individual members were sent notices on July 10 and 23, and corporate members on August 20. Some notices could not be delivered, for example because the address was out of date, so the company also posted the notice on its website. Former members who did not receive a notice can check with the Meitetsu Kyosho customer desk (personal-information line, 0120-353-276 in Japan, weekdays 9:00–17:00).

QDid the data actually leak?
A

The company says it has not confirmed any leak or misuse of personal information so far, but that it cannot rule out a leak. It will announce new facts, including whether a leak occurred, on its website.

QWhy is leaked driver's license information dangerous?
A

Driver's license details are used for identity checks when opening accounts and signing up for services. Combined with your name, address and date of birth, they can help someone apply for contracts in your name. Unlike a password, you cannot change your license number or date of birth. Cariteco's notice says 'driver's license information' and does not state whether license images are included. As a precaution, consider registering a fraud alert with Japan's three credit bureaus (CIC, JICC and the Japanese Bankers Association's credit information center).

QI left the service. Can I have my data deleted?
A

Under Article 35(5) of Japan's Act on the Protection of Personal Information, you can request that a business stop using or delete your data when a reportable leak has occurred or when the business no longer needs the data. Some records may have to be kept by law, but you can ask the company's desk what remains and until when.

QWhat caused it?
A

The company has disclosed that ransomware was involved and that attacks on multiple servers were confirmed, but not how the attackers got in. It says it will identify the cause and strengthen security with advice from outside specialists.