Japanese railway operators Keio Corporation and Tokyo Metro disclose security breaches
Keio confirmed a ransomware attack disrupting business systems, while Tokyo Metro exposed about 59,000 loyalty emails.
Keio Corporation, a major private railway operator in Tokyo, confirmed a ransomware attack detected in the early hours of September 26, 2026, that disrupted some business systems. Keio shut down parts of its network; train services are operating normally, and no information leak has been confirmed. Keio Plaza Hotel was also affected and warned of slower responses to inquiries. Separately, Tokyo Metro said an unauthorized party accessed email addresses of about 59,000 Metpo loyalty members and warned customers about possible phishing follow-ups. No ransomware group has claimed the Keio attack.