Tokyo Metro Metpo email address breach
Tokyo Metro disclosed that an unauthorised third party had accessed the email addresses of roughly 59,000 customers enrolled in its Metpo loyalty programme, warning members to watch for follow-on phishing attempts.
- Victim
- Tokyo Metro Co., Ltd.
- records
- 59.0K
- users
- 59.0K
On 27 September 2026, Tokyo Metro Co., Ltd. β the operator of one of the world's busiest subway networks β announced that an unauthorised third party had accessed the email addresses of roughly 59,000 customers enrolled in its Metpo loyalty programme. The company said no other personal information was accessed and urged affected members to be alert for possible phishing emails or other scams exploiting the exposed addresses.
The disclosure came the same weekend that fellow Japanese transport operator Keio Corporation confirmed a ransomware attack and car-rental firm Times Car reported a separate intrusion, though it was not established whether the incidents were connected.
What happened
Tokyo Metro said it detected unauthorised access to the system supporting its Metpo membership programme and moved to contain it, identifying the suspected point of entry and taking steps to prevent another incident. The exposure was limited to email addresses; the company stated that no other personal data β such as names, payment details or travel records β was compromised.
Because email addresses alone are enough to fuel targeted phishing, Tokyo Metro cautioned members that they might receive fraudulent messages impersonating the operator and advised against clicking suspicious links or divulging further information.
Impact
- Email addresses of approximately 59,000 Metpo loyalty-programme members were accessed by an unauthorised third party.
- No other personal information was reported as compromised.
- Tokyo Metro identified the suspected entry point, took containment steps, and warned members about potential phishing follow-ups.
Timeline
Tokyo Metro announces that an unauthorised third party accessed the email addresses of about 59,000 Metpo loyalty-programme members.
The company says it identified the suspected entry point, took steps to prevent a recurrence, and warned members about possible phishing follow-ups.
Sources
- securityaffairs.comhttps://securityaffairs.com/200027/data-breach/japanese-railway-operators-keio-corporation-and-tokyo-metro-disclose-security-breaches.html
- infosecurity-magazine.comhttps://www.infosecurity-magazine.com/news/japanese-railway-operators-cyber/
- mlex.comhttps://www.mlex.com/mlex/data-privacy-security/articles/2530467