HomeSecurityJapan: Ransomware attack on Keio Corporation

Japan: Ransomware attack on Keio Corporation

Keio Corporation , one of Japan 's major private railway operators , announced that it was hit by a ransomware attack on September 26, 2026, after problems arose in the group's IT systems. The cyberattack led to the disabling of parts of the company's network in order to limit the risk of further breaches, while an investigation is underway to determine the extent of the damage.

Japan: Ransomware attack on Keio Corporation

The incident appears to have mainly affected the company's hospitality sector, with reports of problems with some services and payment systems. So far, there is no indication that the attack directly caused a disruption to rail operations. However, Keio is investigating whether the attackers gained access to customer, partner data or other confidential information.

The case gains added interest because another major transportation network in the Japanese capital, Tokyo Metro, announced a separate cybersecurity incident the same weekend, resulting in the exposure of email addresses of about 59,000 members.

The ransomware attack and Keio's response

According to the company's official announcement , the attack was detected in the early hours of Saturday, September 26, 2026. Keio confirmed that its group's servers had been attacked by ransomware and announced that it had notified the police.

At the same time, a technical investigation with the help of external experts, aiming to identify the route followed by the attackers and clarify which systems were affected.

See also: MCP Python SDK: Stealing OAuth credentials from malicious servers

The company chose to disable the network that was deemed vulnerable, temporarily limiting the operation of certain services. This practice is often used in ransomware incidents, as isolating systems can prevent the further spread of malware and limit potential additional damage.

It remains unknown, however, exactly when the attackers gained initial access, whether any data was leaked, and whether the perpetrators were able to encrypt files or disrupt critical business functions. It has also not been publicly announced which ransomware group is behind the attack.

Problems with hosting and payment services

Keio operates in more than one business sector. It operates a railway network of approximately 85 kilometers with 69 stations, and also has a separate hospitality sector, which includes 25 hotels.

Initial reports indicate that the impact of the cyberattack was mainly limited to the latter area. In a separate announcement on the Keio Plaza Hotel Tokyo website, guests were informed of possible delays in some services.

Meanwhile, Japanese media reported problems with payment systems . If it is confirmed that electronic transaction functions or customer service processes were affected, the incident could have implications beyond simply disrupting access to internal systems.

In hotel businesses, digital infrastructure typically supports reservations, payments, billing, room management, and guest communication. Disruption of even some of these functions can create delays, increased workload for staff, and difficulties in daily service.

Keio employs more than 2,200 people and has annual revenue of about $2.6 billion, according to publicly available data. The group's size highlights the complexity of recovery, as different business activities may depend on shared IT infrastructure.

See also: Bitget: $388 million stolen through vulnerability in vendor's security product

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Aurora ransomware on VMware ESXi

What we know about a possible data leak

One of the key questions the company is examining is whether the attackers gained access to personal data of customers or business partners.

The existence of a ransomware attack does not in itself prove that information was leaked. In many modern attacks, perpetrators attempt to copy data before encrypting systems so that they can put additional pressure on the victim through threats of disclosure.

So far, Keio has not provided a definitive answer to the potential data exposure. For customers, this means being cautious of any messages that appear to come from the company, especially if they ask for login details, payment information, or confirmation of personal data.

Organizations investigating such incidents also need to examine logs, account connections, and database access to determine if there was unauthorized information extraction.

Tokyo Metro and the exposure of 59,000 email addresses

At the same time, Tokyo Metro disclosed a separate cyberattack, in which attackers gained unauthorized access to its systems and stole email addresses of approximately 59,000 members.

The company clarified that the affected systems contained email addresses and said it had identified and remediated the security flaw exploited by the attackers.

Tokyo Metro operates nine subway lines, with a total length of approximately 195 kilometers and 180 stations, serving an average of seven million passengers per day. The scale of its operations highlights the importance of protecting the information systems that support large transportation infrastructure.

Despite the coincidence of the two incidents, there is currently no sufficient evidence to prove that the attacks on Keio and Tokyo Metro are linked or part of a coordinated campaign.

See also: Times Car: Data leak for 6.6 million accounts

Japan: Ransomware attack on Keio Corporation

Lessons on cybersecurity for critical businesses

Attacks on large transportation and hospitality groups show that ransomware risks are not limited to losing access to files. They can affect payments, customer service, and business processes that rely on digital systems.

Isolating affected networks, maintaining secure backups, implementing multi-factor authentication, and restricting access rights are key defenses. Equally important is having a business continuity planso that services can operate with alternative processes when information systems are down.

The next critical step for Keio is to clarify the extent of the breach, confirm whether personal data was affected, and safely restore its services. The results of the investigation will indicate whether the incident was limited to specific business systems or whether its impacts were broader.

source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS