BTC$84,744-0.06% LTC$70.31+4.13% XMR$539.16-1.74%
TorPortal TorPortalMarkets, mirrors, dark web news
BleepingComputer · Sep 28, 2026 · 2 min read · Original story

Japan's Keio confirms ransomware attack disrupted business systems

Japan's Keio confirms ransomware attack disrupted business systems

Keio Corporation (Keio), a major private railway operator in Japan, said its network was hit by a ransomware attack over the weekend, disrupting some of its business systems.

Following a system failure in the early hours of Saturday, the company confirmed the attack and shut down its network to prevent additional damage.

The company said it is investigating the extent of the impact and whether the attackers accessed any customer or business partner information.

Keio is a large Japanese railway operator with 85 km of track and 69 stations, as well as a separate hospitality business of 25 hotels. The company has over 2,200 employees and a reported annual revenue of about $2.6 billion.

“In the early hours of September 26, 2026, we confirmed a ransomware attack on our group's servers. We have reported the incident to the police and are conducting an investigation into the attack's route and damage with the cooperation of external experts,” Keio says.

The incident appears to have affected only the hospitality side of Keio’s business, not train operations.

A separate announcement published on the company’s Keio Plaza Hotel Tokyo website is warning of possible delays on some customer-facing services.

Local media outlets have reported that the cyberattack disrupted the firm's payment systems.

At the time of writing, BleepingComputer could not find a ransomware group claiming the attack on Keio.

BleepingComputer has contacted the company to request more information about the incident, and we will update this post with their response once it reaches us.

Tokyo Metro has also disclosed a cyber incident over the weekend in which attackers gained unauthorized access to its systems and accessed 59,000 member email addresses.

Although both Keio and Tokyo Metro are Japanese railway operators, it is unclear if the organizations were targeted in a coordinated campaign by the same threat actor.

Tokyo Metro is a major transit operator that runs nine subway lines covering 195 km and 180 stations, carrying an average of 7 million passengers daily.

The company said the breached systems contained only email addresses and that it has already identified and closed the security weakness the attackers used in this case.

References in this story

  1. ランサムウェア攻撃によるシステム障害に関するお知らせとお詫び | お知らせ | 京王電鉄 www.keio.co.jp ランサムウェア攻撃によるシステム障害に関するお知らせとお詫び「ニュース」では、京王電鉄に関するニュースリリースやおしらせ、京王グループのおすすめ情報をご覧いただけます。
  2. ランサムウェア攻撃によるシステム障害に関するお知らせとお詫び|新着情報|京王プラザホテル(新宿)【公式】 www.keioplaza.co.jp 京王プラザホテルのランサムウェア攻撃によるシステム障害に関するお知らせとお詫びのご案内です。新着情報の詳細をご案内します。
  3. 京王電鉄にランサム攻撃 決済に障害、鉄道影響なし:東京新聞デジタル www.tokyo-np.co.jp 京王電鉄は26日、グループ会社のサーバーが身代金要求型コンピューターウイルス「ランサムウエア」の攻撃を受け、システム障害が発生したと発...

Guides related to this story

← Back to all news