Skip to content
RansomwareOngoing

Keio Corporation ransomware attack

A ransomware attack in the early hours of 26 September 2026 disrupted business systems across Japan's Keio Group, hitting payment and reservation services in its hospitality division while train operations continued to run normally.

Victim
Keio Corporation

On 26 September 2026, Keio Corporation β€” a major private railway operator in Tokyo and the central firm of the diversified Keio Group β€” confirmed that a ransomware attack in the early hours of Saturday had disrupted some of its business systems. The company detected the system failure over the weekend, shut down its network to contain the intrusion, and reported the incident to police while beginning an investigation with external experts.

The disruption appears to have affected only the hospitality and retail side of Keio's business rather than train operations, which continued to run normally. Local reporting indicated that payment and reservation systems were affected at several group businesses, and the Keio Plaza Hotel Tokyo warned customers of possible delays to some customer-facing services.

What happened

Keio said it identified the incident when a system failure occurred early on Saturday, 26 September, and that subsequent checks confirmed a ransomware infection on group servers. As a precaution, the company disconnected affected systems from its network to stop the attackers from causing further damage. At the time of disclosure, no ransomware group had claimed responsibility for the attack.

The company said it was still investigating the scope of the impact, including whether the attackers accessed any customer or business-partner information; it had not confirmed any data leakage at the time of its notices. Keio operates roughly 85 km of railway lines and 69 stations and employs more than 2,200 people, with a wider group spanning hotels, department stores, real estate and travel services.

Why it matters

The attack landed the same weekend that fellow Japanese transport operators Tokyo Metro and car-rental firm Times Car each disclosed separate security incidents, underscoring the sustained pressure ransomware and intrusion crews are placing on Japan's transport and travel sector. While Keio's core train services were spared, the disruption to payment and reservation systems illustrates how attacks on a conglomerate's back-office and hospitality infrastructure can ripple across a group even when the flagship operation keeps running.

Impact

  • A ransomware attack disrupted business systems across Keio Group companies, with payment and reservation services affected in the hospitality and retail divisions.
  • Train operations continued normally; the company shut down parts of its network to contain the intrusion.
  • Keio reported the incident to police and was still investigating whether any customer or business-partner data was accessed; no threat actor had claimed responsibility.

Timeline

  1. Keio detects a system failure in the early hours of Saturday and confirms a ransomware attack, shutting down its network to prevent further damage.

  2. The company reports the incident to police and begins investigating the intrusion with external experts.

  3. Keio Plaza Hotel and other group businesses warn of possible delays to customer-facing payment and reservation services.

Sources

  1. bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/japans-keio-confirms-ransomware-attack-disrupted-business-systems/
  2. securityaffairs.comhttps://securityaffairs.com/200027/data-breach/japanese-railway-operators-keio-corporation-and-tokyo-metro-disclose-security-breaches.html
  3. scworld.comhttps://www.scworld.com/brief/japanese-railway-operator-keio-hit-by-ransomware-attack
  4. teiss.co.ukhttps://www.teiss.co.uk/news/ransomware-attack-disrupts-payment-systems-at-japans-keio-railway-group-18233

Related incidents