Japanese rail firm Keio hit by ransomware attack
Keio shut down its network after ransomware hit group servers on September 26, while Tokyo Metro separately disclosed access to 59,000 member emails.
By Dev Okafor · Published · Updated · 4 min read

Keio Corporation, one of Japan's major private railway operators, has confirmed a ransomware attack that disrupted some business systems, Geek Feed reports.
What happened
After a system failure early on September 26, 2026, Keio confirmed ransomware on its group servers and shut down its network to limit the damage. It has reported the attack to police and is investigating whether customer or partner data was accessed.
The attack appears to have hit Keio's hotel business, not train operations. Local media say payment systems were disrupted, and the Keio Plaza Hotel Tokyo warned of possible delays to customer services. No ransomware group has claimed the attack yet.
Keio runs 85 km of track and 69 stations, plus 25 hotels, with annual revenue of about $2.6 billion.
A second Tokyo incident
The same weekend, Tokyo Metro disclosed that attackers gained unauthorized access to its systems and viewed 59,000 member email addresses. The two incidents have not been linked.
Why it matters
Transport companies run a mix of public-facing services, payment systems and operational technology. Keeping business IT separate from train control systems — as appears to have happened here — is what stops a ransomware attack from becoming a safety incident.
What customers should do
Keio hotel guests and Tokyo Metro members should watch for phishing emails that mention bookings or memberships, and avoid clicking links in unexpected messages.



