Keio Electric Railway Confirms Ransomware Attack Disrupted Business Systems in Japan
Keio Electric Railway, one of Japan’s major private railway operators, has confirmed that its network was hit by a ransomware attack over the weekend, disrupting some of the company’s business systems.
Ransomware attack confirmed after system outage
Keio reported a system outage early Saturday morning. The company later confirmed that the disruption was caused by a ransomware attack and shut down the affected network to prevent further damage.
Keio said it is investigating the scope of the incident, including whether attackers accessed information belonging to customers or business partners.
“In the early hours of September 26, 2026, we confirmed a ransomware attack on our group’s servers. We have reported it to the police and are currently investigating the attack route and damage situation with the cooperation of external experts,” Keio said.
Hospitality systems appear to be affected
The incident appears to have affected the hospitality side of Keio’s operations rather than its train services.
Keio Electric Railway operates approximately 85 kilometers of railway lines and 69 stations. The company also runs an independent hospitality business with 25 hotels, employs more than 2,200 people, and reports annual revenue of approximately $2.6 billion.
In a separate announcement, Keio Plaza Hotel warned that some customers may experience service delays.
Local media also reported that the cyberattack disrupted the company’s payment system.
As of this writing, BleepingComputer was unable to locate any ransomware groups claiming responsibility for the attack against Keio Electric Railway.
BleepingComputer has contacted Keio for more information about the incident and will update this article if the company provides a response.
Tokyo Metro reports separate cyber incident
Tokyo Metro also disclosed a cyber incident over the weekend. Attackers compromised some of the company’s systems and gained access to 59,000 member email addresses.
Keio and Tokyo Metro are both Japanese transportation operators, but it remains unclear whether the incidents were part of a coordinated campaign or involved the same attackers.
Tokyo Metro operates 195 kilometers of track across nine subway lines and 180 stations, serving an average of 7 million passengers daily.
Tokyo Metro said the compromised systems contained only email addresses. The company also said it had identified and resolved the security vulnerabilities exploited in the incident.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, correct, and revalidate at machine speed.
Source: www.bleepingcomputer.com



