Ransomware Hits Keio Group While Tokyo's Railway Network Stays Isolated
Keio Corporation, one of the major private railway operators serving the greater Tokyo metropolitan area, confirmed that a ransomware attack struck servers across its group companies in the early hours of Saturday, September 26, 2026. The intrusion disrupted point-of-sale, reservation, and payment systems at several Keio Group businesses — but the company says its railway operations run on a physically separate system that was never touched, so train service continued without interruption. Keio notified police immediately, isolated affected network segments, and brought in external cybersecurity specialists to scope the damage. As of publication, no data leak has been confirmed and no ransomware group has publicly claimed the attack.
Incident Details
| Attribute | Value |
|---|---|
| Target | Keio Corporation and affiliated Keio Group companies (Tokyo, Japan) |
| Attack Type | Ransomware (encryption of internal servers) |
| Date Detected | Early hours of Saturday, September 26, 2026 |
| Public Disclosure | September 28, 2026 |
| Threat Actor | Unattributed — no group has claimed the attack as of reporting |
| Railway/Train Operations | Not affected — runs on an isolated, separate system |
| Systems Affected | Retail payment terminals, hotel reservation/inquiry systems, bus fare payment counters |
| Data Exposure | Unconfirmed; investigation into customer/business data access ongoing |
| Response Actions | Network isolation, police notification, external incident-response engagement |
What Happened
Detection and Containment
Keio said it detected anomalous activity on its systems in the early morning of September 26 and moved quickly to contain it, cutting off network access for affected servers to stop the ransomware from spreading further. The company reported the incident to police the same day and engaged outside cybersecurity experts to determine the initial access vector and the full scope of what was touched. Keio has not disclosed which ransomware strain was used or how the attackers first gained access to its environment.
What Was Hit Across the Group
The disruption spread across several customer-facing arms of the Keio Group rather than staying confined to a single business unit:
- Keio Store (the group's supermarket chain) — card and e-money payments, along with loyalty-point accrual, were knocked offline at some locations, forcing cash-only transactions.
- Keio Plaza Hotel — confirmed a direct attack on its own servers, causing delays in responding to guest inquiries, though the company said core hotel operations were not interrupted.
- Keio Presso Inn (the group's budget hotel brand) — suspended new reservations and email inquiries while systems were assessed.
- Keio Bus — credit card payments became unusable at commuter pass sales counters.
What Wasn't Hit — and Why
Keio was explicit that its railway operations were unaffected. The company's train-control, signaling, and dispatch systems run on infrastructure that is architecturally and operationally separate from the corporate and retail networks the attackers reached. This separation between safety-critical operational technology and business IT is standard practice among large transit operators, and it is the reason a ransomware infection that disrupted point-of-sale terminals and hotel booking systems never put passengers or train movements at risk.
Attribution and Data Exposure
No ransomware group has posted a claim for the Keio attack on its extortion site as of this writing, which is notable given that most modern ransomware operations publicize victims within days to pressure payment. Keio said it is still investigating whether attackers accessed or exfiltrated confidential company information or customer data, and has committed to disclosing further findings as the investigation progresses. The incident adds to a documented rise in ransomware activity against Japanese organizations — Japanese police recorded 226 ransomware cases in 2025, the second-highest annual total on record, with researchers pointing to Japan's central role in global supply chains and its industries' low tolerance for operational downtime as factors that make them attractive targets.
Impact Assessment
| Impact Area | Description |
|---|---|
| Passenger Safety | No impact — train, signaling, and dispatch systems are isolated from the compromised network |
| Retail Operations | Card and e-money payments, plus loyalty programs, disabled at some Keio Store locations |
| Hospitality | Keio Plaza Hotel and Keio Presso Inn faced delayed guest responses and suspended new bookings |
| Bus Services | Commuter pass sales counters unable to process credit card payments |
| Data Confidentiality | Under investigation — no confirmed leak of customer or partner data at time of writing |
| Reputational | Public disclosure during a period of elevated ransomware activity against Japanese firms invites scrutiny of group-wide security posture |
| Regulatory | Police investigation now open; potential notification obligations if customer data compromise is confirmed |
Recommendations
For Critical Infrastructure and Transit Operators
- Maintain strict network segmentation between operational technology (signaling, dispatch, train control) and corporate/retail IT — and periodically test that the separation holds under real incident conditions, not just on paper.
- Maintain offline, tested backups for point-of-sale, reservation, and loyalty systems so payment channels can be restored without negotiating with attackers.
- Pre-stage manual fallback procedures (cash-only operation, paper ticketing) for customer-facing services that depend on networked payment terminals.
For Retail and Hospitality Security Teams
- Treat payment terminals and booking/reservation platforms as high-value targets; monitor them for the kind of lateral-movement indicators that typically precede ransomware deployment.
- Review third-party and inter-subsidiary network trust relationships — group-wide attacks like this one often ride connections between a parent company and its retail, hotel, or transport subsidiaries.
- Prepare customer communication templates in advance so delays in reservations, inquiries, or payment processing can be explained quickly and transparently during an incident.
For Keio Customers and Riders
- If you hold a Keio Store loyalty account, Keio Presso Inn reservation, or have used a card at an affected location recently, watch for official notices from Keio regarding any confirmed data exposure.
- Expect cash-only or degraded service at some Keio Store and Keio Bus locations until systems are fully restored, and confirm hotel reservations directly with Keio Presso Inn or Keio Plaza Hotel if booked around the incident window.
- Be alert to phishing attempts that may exploit public awareness of this incident by impersonating Keio Group communications.
Key Takeaways
- Keio Corporation confirmed a ransomware attack detected in the early hours of September 26, 2026, affecting servers across several Keio Group companies.
- Railway/train operations were not affected because they run on a system that is physically and operationally separate from the compromised corporate and retail networks — passenger safety was never at risk.
- Retail, hotel, and bus payment systems bore the brunt of the disruption, including Keio Store, Keio Plaza Hotel, Keio Presso Inn, and Keio Bus.
- No ransomware group has claimed the attack and Keio has not disclosed the initial access vector or ransomware strain involved.
- Data exposure remains unconfirmed — Keio is still investigating whether customer or business partner information was accessed, with further disclosures expected.
- The incident fits a broader pattern of rising ransomware activity against Japanese organizations, with police recording 226 cases in 2025, reinforcing why segmentation between OT and IT matters for transit and infrastructure operators.
Sources
- BleepingComputer — Japan's Keio confirms ransomware attack disrupted business systems
- BigGo Finance — Ransomware Attack Hits Japan's Keio Corporation Group, Disrupting Services
- Rus Tourism News — Ransomware Hits Japanese Keio Group, Disrupting Hotel Bookings and Card Payments
- The Japan Times — Ransomware attacks reported in Japan number 226 in 2025