Japanese company Keio confirmed that its group servers were hit by a ransomware attack on September 26, 2026, disrupting some business systems, particularly in the hospitality sector, with no indications that train operations were affected. The company is still investigating the extent of the damage and the possibility that customer and partner data was accessed.
Keio Corporation, one of Japan’s major private railway operators, confirmed that the group’s servers were subjected to a ransomware attack during the early hours of September 26, 2026. The incident disrupted some business systems, prompting the company to shut down its network to limit the possibility of the attack spreading or causing additional damage.
Keio said it had notified the police and was investigating the intrusion’s path and scope in cooperation with external experts. The company has not yet determined whether the attackers managed to access information belonging to customers or business partners.
The Apparent Impact Is Concentrated in the Hospitality Sector
The available information indicates that the impact affected the hospitality side of Keio’s business, rather than train operations. The company operates a network extending 85 kilometers and comprising 69 stations, in addition to a separate hotel business with 25 hotels. It employs more than 2,200 people and has reported annual revenue of approximately $2.6 billion.
The website of Keio Plaza Hotel Tokyo published a notice warning of possible delays to some services provided to customers. Local media also reported that the attack disrupted the company’s payment systems, but the details and operational scope of the outage have not been fully determined.
What Has Not Yet Been Clarified?
As of the time of publication, no ransomware group had claimed responsibility for the attack, and no final result was available from the investigation into the data that may have been accessed. Therefore, it is not yet possible to confirm whether personal or business information was leaked. The company’s practical priorities remain identifying the entry point, containing the affected systems, and verifying the safety of services before bringing the network back online.
A Separate Incident at Tokyo Metro
At the same time, Tokyo Metro announced another cyber incident during the weekend, saying that attackers had gained unauthorized access to its systems and accessed the email addresses of approximately 59,000 members. The company explained that the affected systems contained email addresses only, and that it had identified and closed the vulnerability used.
There is currently no evidence that the Keio and Tokyo Metro incidents were part of a coordinated campaign or were carried out by the same entity. Although both companies operate in Japan’s transportation sector, the connection between the two incidents remains unconfirmed.
Why Does This Matter?
The incident shows that the impact of ransomware attacks on transportation companies is not necessarily limited to train operations or field infrastructure; it may first appear in payment systems, reservations, hotel services, and other back-end systems. However, the source does not yet provide enough information to assess the scale of the losses or the nature of the affected data, making any broader estimate premature.