NEWS

Japan's Keio Confirms Ransomware Attack Disrupted Business Systems

Keio Group confirmed a ransomware attack hit servers on September 26, disrupting hotel, retail, and bus payment systems; trains stayed unaffected.

Dylan H.

News Desk

September 28, 2026
7 min read
Japan's Keio Confirms Ransomware Attack Disrupted Business Systems

Ransomware Hits Keio Group While Tokyo's Railway Network Stays Isolated

Keio Corporation, one of the major private railway operators serving the greater Tokyo metropolitan area, confirmed that a ransomware attack struck servers across its group companies in the early hours of Saturday, September 26, 2026. The intrusion disrupted point-of-sale, reservation, and payment systems at several Keio Group businesses — but the company says its railway operations run on a physically separate system that was never touched, so train service continued without interruption. Keio notified police immediately, isolated affected network segments, and brought in external cybersecurity specialists to scope the damage. As of publication, no data leak has been confirmed and no ransomware group has publicly claimed the attack.


Incident Details

AttributeValue
TargetKeio Corporation and affiliated Keio Group companies (Tokyo, Japan)
Attack TypeRansomware (encryption of internal servers)
Date DetectedEarly hours of Saturday, September 26, 2026
Public DisclosureSeptember 28, 2026
Threat ActorUnattributed — no group has claimed the attack as of reporting
Railway/Train OperationsNot affected — runs on an isolated, separate system
Systems AffectedRetail payment terminals, hotel reservation/inquiry systems, bus fare payment counters
Data ExposureUnconfirmed; investigation into customer/business data access ongoing
Response ActionsNetwork isolation, police notification, external incident-response engagement

What Happened

Detection and Containment

Keio said it detected anomalous activity on its systems in the early morning of September 26 and moved quickly to contain it, cutting off network access for affected servers to stop the ransomware from spreading further. The company reported the incident to police the same day and engaged outside cybersecurity experts to determine the initial access vector and the full scope of what was touched. Keio has not disclosed which ransomware strain was used or how the attackers first gained access to its environment.

What Was Hit Across the Group

The disruption spread across several customer-facing arms of the Keio Group rather than staying confined to a single business unit:

  • Keio Store (the group's supermarket chain) — card and e-money payments, along with loyalty-point accrual, were knocked offline at some locations, forcing cash-only transactions.
  • Keio Plaza Hotel — confirmed a direct attack on its own servers, causing delays in responding to guest inquiries, though the company said core hotel operations were not interrupted.
  • Keio Presso Inn (the group's budget hotel brand) — suspended new reservations and email inquiries while systems were assessed.
  • Keio Bus — credit card payments became unusable at commuter pass sales counters.

What Wasn't Hit — and Why

Keio was explicit that its railway operations were unaffected. The company's train-control, signaling, and dispatch systems run on infrastructure that is architecturally and operationally separate from the corporate and retail networks the attackers reached. This separation between safety-critical operational technology and business IT is standard practice among large transit operators, and it is the reason a ransomware infection that disrupted point-of-sale terminals and hotel booking systems never put passengers or train movements at risk.

Attribution and Data Exposure

No ransomware group has posted a claim for the Keio attack on its extortion site as of this writing, which is notable given that most modern ransomware operations publicize victims within days to pressure payment. Keio said it is still investigating whether attackers accessed or exfiltrated confidential company information or customer data, and has committed to disclosing further findings as the investigation progresses. The incident adds to a documented rise in ransomware activity against Japanese organizations — Japanese police recorded 226 ransomware cases in 2025, the second-highest annual total on record, with researchers pointing to Japan's central role in global supply chains and its industries' low tolerance for operational downtime as factors that make them attractive targets.


Impact Assessment

Impact AreaDescription
Passenger SafetyNo impact — train, signaling, and dispatch systems are isolated from the compromised network
Retail OperationsCard and e-money payments, plus loyalty programs, disabled at some Keio Store locations
HospitalityKeio Plaza Hotel and Keio Presso Inn faced delayed guest responses and suspended new bookings
Bus ServicesCommuter pass sales counters unable to process credit card payments
Data ConfidentialityUnder investigation — no confirmed leak of customer or partner data at time of writing
ReputationalPublic disclosure during a period of elevated ransomware activity against Japanese firms invites scrutiny of group-wide security posture
RegulatoryPolice investigation now open; potential notification obligations if customer data compromise is confirmed

Recommendations

For Critical Infrastructure and Transit Operators

  • Maintain strict network segmentation between operational technology (signaling, dispatch, train control) and corporate/retail IT — and periodically test that the separation holds under real incident conditions, not just on paper.
  • Maintain offline, tested backups for point-of-sale, reservation, and loyalty systems so payment channels can be restored without negotiating with attackers.
  • Pre-stage manual fallback procedures (cash-only operation, paper ticketing) for customer-facing services that depend on networked payment terminals.

For Retail and Hospitality Security Teams

  • Treat payment terminals and booking/reservation platforms as high-value targets; monitor them for the kind of lateral-movement indicators that typically precede ransomware deployment.
  • Review third-party and inter-subsidiary network trust relationships — group-wide attacks like this one often ride connections between a parent company and its retail, hotel, or transport subsidiaries.
  • Prepare customer communication templates in advance so delays in reservations, inquiries, or payment processing can be explained quickly and transparently during an incident.

For Keio Customers and Riders

  • If you hold a Keio Store loyalty account, Keio Presso Inn reservation, or have used a card at an affected location recently, watch for official notices from Keio regarding any confirmed data exposure.
  • Expect cash-only or degraded service at some Keio Store and Keio Bus locations until systems are fully restored, and confirm hotel reservations directly with Keio Presso Inn or Keio Plaza Hotel if booked around the incident window.
  • Be alert to phishing attempts that may exploit public awareness of this incident by impersonating Keio Group communications.

Key Takeaways

  1. Keio Corporation confirmed a ransomware attack detected in the early hours of September 26, 2026, affecting servers across several Keio Group companies.
  2. Railway/train operations were not affected because they run on a system that is physically and operationally separate from the compromised corporate and retail networks — passenger safety was never at risk.
  3. Retail, hotel, and bus payment systems bore the brunt of the disruption, including Keio Store, Keio Plaza Hotel, Keio Presso Inn, and Keio Bus.
  4. No ransomware group has claimed the attack and Keio has not disclosed the initial access vector or ransomware strain involved.
  5. Data exposure remains unconfirmed — Keio is still investigating whether customer or business partner information was accessed, with further disclosures expected.
  6. The incident fits a broader pattern of rising ransomware activity against Japanese organizations, with police recording 226 cases in 2025, reinforcing why segmentation between OT and IT matters for transit and infrastructure operators.

Sources