Security Guides
The outage ends, the leak answer comes later — what Cariteco (Meitetsu Kyosho) members should do after the ransomware attack
Ransomware hit Meitetsu Kyosho's servers, and driver's license data of current and former members of its car-sharing service Cariteco may have leaked, with card data for some members. Based on the company's notices: what members should do today.
For: current and former users of Meitetsu Kyosho's car-sharing service Cariteco in Japan, and staff at companies with corporate Cariteco contracts. This article is based on Meitetsu Kyosho Co., Ltd.'s official notices and does not cover attack techniques.
What members should do today
Check whether you are affected — former members count, and the letter may not have reached you
Affected people are current and former Cariteco members. The company sent individual notices by post or similar means to individual members on July 10 and 23 and to corporate members on August 20. But some could not be delivered, for example because of outdated addresses, so it also posted the notice online. If you moved after joining or left years ago, you may not have received one. If in doubt, call the Meitetsu Kyosho customer desk (personal-information line) at 0120-353-276 (weekdays 9:00–17:00, Japan).
Do not respond to calls, emails or letters claiming to be the company or a card issuer
The data in scope combines name, address, phone number and email address, which is enough to write convincing messages — including paper letters. The company asks members to be wary of suspicious calls, emails and mail, and not to readily comply with requests to enter or give personal information, authentication details or card information. If you need to check something, contact an official number you looked up yourself (see What is phishing?).
If you registered a card, check your statements
The company says card information may be included for some members, without saying which members or which items. If you registered (or may have registered) a card with Cariteco, check your statements for charges you do not recognize, and call the number on the back of the card if you find any. If you remain worried, you can explain the situation to your issuer and ask about replacing the number.
Register a fraud alert (self-declaration) with Japan's three credit bureaus
This is available when your name may be misused because an identity document was lost, stolen or leaked. Once registered, lenders and card issuers see the note when checking your file and review applications more carefully. CIC, JICC and the Japanese Bankers Association's credit information center have different member companies, so register with all three. Differences between the bureaus and how long alerts last are covered in the Times Car article.
Request your credit file and look for accounts you did not open
A fraud alert does not block applications. Request your own credit file from each bureau — once now and again a few months later — and look for cards or loans you never applied for. If an unfamiliar contract or collection notice arrives, contact that business and your local police station.
If you are a former member, ask for your data to be deleted
Japan's privacy law lets you request that a business stop using or delete your data when a reportable leak has occurred or when the business no longer needs the data (Article 35, paragraph 5). Former members can ask the desk whether their application-form data is still held and whether it can be deleted. Some records may have to be kept by law, but getting an answer on what remains and until when is worth it on its own.
Corporate account staff: warn colleagues about 'our bank account has changed' messages
Per the September 3 notice, corporate customers' company name, address, contact details, representative's information and bank account information, plus the license information of employees registered to use Cariteco, are in scope. Circulate a rule that emails or letters claiming "our payment account has changed" are verified through another channel, such as a phone call. Tell registered employees about the fraud-alert option too.
What happened (from Meitetsu Kyosho's notices)
Everything below is as stated in the official notices of the company and of Cariteco.
Jun 23, 2026
The company detected suspicious access to its servers. Some servers stopped, and it immediately isolated systems and cut network connections.Jun 29
Cariteco announced that, because of the outage, new sign-ups and changes to existing members' names, addresses and phone numbers, as well as new corporate sign-ups, were suspended.Jul 2
The company disclosed the outage caused by unauthorized access. It said the outside investigation had "confirmed traces of unauthorized access by ransomware on June 19". At that point no leak of information outside the company had been confirmed; the police and relevant authorities were consulted and informed.Jul 6
A customer call center was opened.Jul 10 and 23
Individual notices about a possible leak were sent to individual Cariteco members.Jul 22
Cariteco resumed new sign-ups and contract-change procedures.Jul 28
The company said the investigation had found attacks on multiple servers and that it could not rule out a leak of customer information.Aug 4
Cariteco posted a notice on its site about the possible leak of member information, explaining that some individual notices could not be delivered and the post was meant to cover them.Aug 20
Individual notices were sent to corporate Cariteco customers (also posted online on September 3).
- Individual members
- What was written on the application form: name, address, date of birth, phone number, email address, driver's license information
- Card data
- May be included for some members (which members and which items not disclosed)
- Corporate customers
- Company name, address, contact details, representative's information, bank account information provided when the relationship began, and the license information of employees registered to use Cariteco
- Scope
- Current and former members. No count disclosed
- Stated cause
- Unauthorized access by ransomware; attacks on multiple servers confirmed. Entry route and other details not disclosed
- Secondary harm
- The company says no leak or misuse of personal information has been confirmed
- Other services
- Besides Cariteco, the company has sent individual notices to users of several other services, such as monthly parking customers and point-card members
- Contact
- Meitetsu Kyosho customer desk (personal-information line) 0120-353-276 (weekdays 9:00–17:00, Japan)
How to read it: what 'driver's license information' means is not stated
In the Times Car case, the operator explicitly said driver's license images were included. Cariteco's notice says only "driver's license information", so it is unclear whether that means the details printed on the license, such as number and expiry date, or also images. Either way, a license number combined with your name, address and date of birth cannot be changed, so the steps in this article are the same. We will update if details are published.
What is specific to this case: with ransomware, "fixed" and "leaked?" arrive separately
Jun 23 outage
Servers stopped and isolated; sign-ups suspended
↓→
Jul 2 disclosure
Ransomware traces; leak "not confirmed"
↓→
Jul 22 restart
Cariteco sign-ups and changes
From Jul 28: "cannot rule out a leak" / individual notices (some undeliverable)
→ "The service is back" does not mean "the data was safe". Members' precautions start at this stage
A ransomware attack first shows up as "it doesn't work": bookings fail, sign-ups stop, sites go down. That is what users learn first. Whether data was taken only becomes clear after the stopped servers are examined one by one. In Meitetsu Kyosho's case, on July 2 the company said "no leak of information outside the company has been confirmed", and it was on July 28 — after Cariteco had resumed sign-ups — that it said a leak could not be ruled out.
The lesson for users: when an outage notice appears, recall what you have entrusted to that service. Services you have left are especially risky, because your contact details there may be out of date and the later leak notice may never reach you. How ransomware works and how organizations prepare are covered in What is ransomware?.
The two car-sharing cases side by side
In 2026, two car-sharing cases involving driver's license data were disclosed in Japan. Laid side by side, what members should do is the same; the differences are in certainty and how people were notified.
| Item | Times Car | Cariteco (Meitetsu Kyosho) |
|---|---|---|
| Starting point | Unauthorized access to the website | System outage from ransomware |
| Certainty | Confirmed obtained by a third party | Cannot rule out a leak |
| Count | ~6.6M accounts (~1.6M with ID-document images) | Not disclosed |
| License | Includes images | "Driver's license information" (images not specified) |
| Card data | Confirmed not leaked | May be included for some members |
| Former members | Included | Included |
| Individual notice | Post or similar (some undeliverable) |
For car-sharing operators: separate "needed for screening" from "kept forever"
The company has not said why it kept former members' application data. A car-sharing service has business reasons of its own, such as confirming a valid license for each rental. With that said, here is what operators can review based on what the two cases have in common.
Set a deletion deadline for former members' application data
Checking a license at sign-up is necessary. But former members' application data is not used by the business, yet it is still in scope when a leak happens. Japan's privacy law asks businesses to make efforts to delete personal data without delay once it is no longer needed (Article 22, a duty of effort). Keep it for the legally required period if there is one, otherwise set a short deadline, and make it delete automatically when the deadline passes.
If you cannot delete it, keep it reachable — check how current contact details are
The company says some individual notices could not be delivered. For any service that keeps member data for years, it is common for the contact details to go stale while the rest of the record stays. This site's view, for operators in general: ID data for people you can no longer reach, and have no duty to keep, is data whose retention should be reviewed. For data you must keep, prompt people to update their contact details; data where you cannot reach the person and have no duty to keep it, delete. Decide both in the same inventory.
Be able to restore when stopped, and limit harm if data is taken
Ransomware preparation has two parts: being able to restore from backups, and separating servers that hold customer data from the general business network. The first is covered in Backup essentials (the 3-2-1 rule), and the organization-wide minimum in The minimum security baseline for organizations.
Sources (public record)
The facts in this article come from the public sources below. Undisclosed intrusion routes or methods are not speculated on.
- Meitetsu Kyosho Co., Ltd., notice on the system outage caused by unauthorized access (July 2, 2026, Japanese) — mkyosho.co.jp
- Meitetsu Kyosho Co., Ltd., opening of a customer call center for the outage (July 6, 2026, Japanese) — mkyosho.co.jp
- Meitetsu Kyosho Co., Ltd., notice on a possible customer data leak from the unauthorized access (July 28, 2026, Japanese) — mkyosho.co.jp
- Meitetsu Kyosho Co., Ltd., status of individual notices about a possible leak (as of August 6, August 12 and September 3, Japanese) — Aug 6 / Aug 12 / Sep 3
- Cariteco, apology and notice on a possible personal-data leak from unauthorized access (August 4, 2026: individual members, Japanese) — cariteco.com / same (September 3, 2026: corporate customers) — cariteco.com
- Cariteco, system outage notice (June 29) and restart of sign-ups and applications after recovery (July 22, Japanese) — Jun 29 / Jul 22
- Credit-bureau self-declaration (Japanese): CIC / JICC / Japanese Bankers Association credit information center
- Act on the Protection of Personal Information, Articles 22 and 35 (Japanese) — e-Gov Law Search
- Times Car figures are from Times Mobility Co., Ltd.'s notices of September 28 and 29, 2026 (details and sources in the Times Car article)
Update history
2026-09-30: First version, based on Meitetsu Kyosho's notices from July 2 to September 3 and Cariteco's notices of August 4 and September 3. The company says it will announce new facts, including whether a leak occurred; this article will be updated when it does.
Read next
- The same pattern: The Times Car breach (driver's license images leaked)
- Another Japanese case this season: APORITO Online Store: possible card data leak
- Follow-on scams: What is phishing?
- Ransomware: What is ransomware? / Backup essentials
- Other 2026 incidents: list of breaches and cyberattacks (Japan and worldwide)
- For operators: The minimum security baseline for organizations
FAQ
QWhat happened at Cariteco?
According to operator Meitetsu Kyosho Co., Ltd., it detected suspicious access to its servers on June 23, 2026; some servers stopped, and it immediately isolated systems and cut network connections. An investigation with outside specialists found traces of unauthorized access by ransomware (disclosed July 2). On August 4 it announced that, as the investigation continued, it could not rule out that Cariteco member information had leaked.
QWhat data may have leaked?
Per the August 4 notice: the information written on the membership application form — name, address, date of birth, phone number, email address and driver's license information. For some members, credit card information may also be included. For corporate customers, a September 3 notice lists the company name, address, contact details, representative's information and bank account information provided when the business relationship began, plus the license information of employees registered to use Cariteco. No count has been disclosed.
QAm I affected?
The company says both current and former Cariteco members are included. Individual members were sent notices on July 10 and 23, and corporate members on August 20. Some notices could not be delivered, for example because the address was out of date, so the company also posted the notice on its website. Former members who did not receive a notice can check with the Meitetsu Kyosho customer desk (personal-information line, 0120-353-276 in Japan, weekdays 9:00–17:00).
QDid the data actually leak?
The company says it has not confirmed any leak or misuse of personal information so far, but that it cannot rule out a leak. It will announce new facts, including whether a leak occurred, on its website.
QWhy is leaked driver's license information dangerous?
Driver's license details are used for identity checks when opening accounts and signing up for services. Combined with your name, address and date of birth, they can help someone apply for contracts in your name. Unlike a password, you cannot change your license number or date of birth. Cariteco's notice says 'driver's license information' and does not state whether license images are included. As a precaution, consider registering a fraud alert with Japan's three credit bureaus (CIC, JICC and the Japanese Bankers Association's credit information center).
QI left the service. Can I have my data deleted?
Under Article 35(5) of Japan's Act on the Protection of Personal Information, you can request that a business stop using or delete your data when a reportable leak has occurred or when the business no longer needs the data. Some records may have to be kept by law, but you can ask the company's desk what remains and until when.
QWhat caused it?
The company has disclosed that ransomware was involved and that attacks on multiple servers were confirmed, but not how the attackers got in. It says it will identify the cause and strengthen security with advice from outside specialists.