Keio ransomware and separate Tokyo Metro and Times Car breaches
Keio confirmed a September 26 ransomware attack that spared trains, while Tokyo Metro and Times Car disclosed separate data exposures.
Keio Corporation, a major Japanese private railway operator with about $2.6 billion in annual revenue, confirmed a ransomware attack on group servers detected in the early hours of September 26, 2026, after a system failure. It notified police and hired external specialists. Sources agree that train operations and operational technology were unaffected and that no data leak has been confirmed, although Keio is still investigating possible access to customer or partner data; no group has claimed the attack, and the operator, encryption status, and any ransom demand were not disclosed. Accounts differ on containment—a broader network shutdown, isolation of segments, or cutting internet access—and on impact, from hospitality and payment trouble, including slower inquiry responses at Keio Plaza Hotel Tokyo, to disruption of some group sales and business systems. Separately, Tokyo Metro said an unauthorized party accessed email addresses of 59,000 Metpo loyalty members, closed the suspected access point, and warned of possible phishing. Times Car said a same-day website intrusion may have exposed personal data on as many as 6.6 million current and former members, including names, contacts, driver's licenses, and identity documents, with passwords stored in a non-recoverable form; no link among the three incidents is confirmed.
- Keio Corporation, a Japanese private railway operator with about $2.6 billion in annual revenue, confirmed ransomware on group servers in the early hours of September 26, 2026, after a system failure.
- Keio notified police, engaged external specialists, and contained the incident; sources differ on whether it shut down the network, isolated segments, or cut internet access.
- Train operations and operational technology were unaffected; no data leak is confirmed, though Keio is still checking whether customer or partner data was accessed.
- No ransomware group has claimed the Keio attack; the operator, encryption status, and any ransom demand were not disclosed.
- Disruption accounts range from hospitality and payment issues, including slower inquiry responses at Keio Plaza Hotel Tokyo, to some group sales and business systems.
- Tokyo Metro said an unauthorized party accessed 59,000 Metpo loyalty email addresses, closed the access point, and warned of possible phishing.
- Times Car said a same-day website intrusion may have exposed names, contacts, driver's licenses, and identity documents for as many as 6.6 million current and former members; passwords were stored in non-recoverable form.
- No link among the Keio, Tokyo Metro, and Times Car incidents is confirmed.
Coverage timelineoldest first · each row is one article
- · 3d agoJapan's Keio confirms ransomware attack disrupted business systems
BleepingComputer· 76
Keio confirmed a weekend ransomware attack that disrupted hospitality systems but not train operations.
- · 2d agoKeio Railway Confirms Ransomware Attack Disrupted Business Systems
GBHackers· 70
Japan's Keio Corporation confirmed a ransomware attack disrupting group business systems; train operations continue and no data breach is confirmed yet.
- · 2d agoJapanese Railway Operators Hit with Weekend Cyber Attacks
Infosecurity Magazine· 78