Japanese car rental giant Nippon Rent-A-Car has announced that its application system has been subjected to a series of cyberattacks, resulting in the exposure of personal information belonging to 96 members.
Two-Phase Cyber Attack Compromises Member Data
The company first detected a security breach on September 26th, which led to the leakage of 41 members’ data. In a subsequent discovery on September 29th, Nippon Rent-A-Car confirmed that a separate group of hackers had infiltrated the system again. This second attack resulted in the exposure of sensitive information for an additional 55 members.
The compromised data includes names, phone numbers, email addresses, login IDs, rental usage history, and reservation details. Nippon Rent-A-Car has stated that it is proactively contacting all affected members individually via their registered email addresses. The company is urging these members to be vigilant against potential phishing attempts, as their leaked information could be exploited by malicious actors.
Nippon Rent-A-Car: A Legacy in Japanese Mobility
Nippon Rent-A-Car, known in Japan as ニッポンレンタカー, is a long-standing player in the car rental industry with over 50 years of operational history. The company boasts an extensive network of approximately 912 branches across Japan, managing a fleet of around 33,400 vehicles. Many of its branches are strategically located near major train stations and airports, facilitating convenient pick-up and drop-off services, including options for returning vehicles at different locations.
Japan’s Evolving Data Protection Landscape
This incident highlights the ongoing challenges businesses face in safeguarding customer data in an increasingly digital world. In Japan, the Act on the Protection of Personal Information mandates that companies implement necessary and appropriate security measures when handling personal data. A significant revision to this law, scheduled for completion in July 2026, is set to introduce a “levy” system, empowering regulatory bodies to impose administrative fines on companies.
Prior to this revision, companies that rectified non-compliant behavior upon receiving recommendations were typically not subject to additional penalties. However, the upcoming amendments will also see stricter penalties for violations. For offenses committed with the intent of gaining unjust benefits, the maximum prison sentence will be raised from under one year to two years, and fines will increase significantly from 500,000 yen to 100 million yen.
The Nippon Rent-A-Car data breach serves as a stark reminder for all organizations to continuously review and strengthen their cybersecurity defenses to protect against evolving threats and comply with stringent data protection regulations.









