Japanese railway operators Keio Corporation and Tokyo Metro disclose security breaches
Japanese railway operators Keio Corporation and Tokyo Metro disclose security breache 2026-9-29 20:54:29 Author: securityaffairs.com(查看原文) 阅读量:7 收藏

Japanese railway operators Keio Corporation and Tokyo Metro disclose security breaches

Pierluigi Paganini September 29, 2026

Keio, a major Japanese railway operator, was hit by ransomware, disrupting business systems and forcing the company to shut down its network.

Keio Corporation, one of Japan’s major private railway operators, was hit by a ransomware attack over the weekend, disrupting some of its business systems.

The company detected a system failure early Saturday and later confirmed the ransomware attack. Keio shut down its network to prevent the attackers from causing further damage.

Keio Corporation immediately launched an investigation into the incident to assess the scope of the security breach.

Keio Corporation is a major private railway operator based in Tokyo, Japan. It operates about 85 km of railway lines and 69 stations, connecting western Tokyo with the Tama area and nearby parts of Kanagawa. The company is part of the Keio Group, which also operates hotels, retail businesses and other services. Keio has more than 2,200 employees.

“Keio Corporation (hereinafter referred to as “the Company”) confirmed in the early hours of September 26, 2026, that a system failure occurred due to a ransomware attack.” reads the company’s notice. “We are currently investigating the scope of the impact, including the leakage of confidential information related to our business and customer information.”

Some Keio Group companies are experiencing disruptions to their business systems following the cyberattack. So far, Keio has not found evidence that any information was leaked, but the investigation is still ongoing.

The company immediately shut down parts of its network to prevent further damage and is working to determine the cause and full impact of the incident. Despite the disruption to business systems, train services are currently operating normally. Keio said it will provide further updates as new information becomes available.

Keio Plaza Hotel was also affected by the attack.

“While some of our systems are experiencing difficulties, we have not confirmed any information leakage at this time. We will continue to investigate.” reads the notice published by Keio Plaza Hotel Tokyo. “Currently, it may take longer than usual to receive a response to inquiries made through the contact form on our official website and through various reservation sites. Additionally, depending on the situation, we may not be able to respond to all inquiries.”

At this time, no ransomware group has claimed responsibility for this attack.

Another Japanese railway operator, Tokyo Metro, on September 27 announced that an unauthorized third party had accessed the email addresses of about 59,000 customers enrolled in its Metpo loyalty program. Tokyo Metro said it identified the suspected entry point and took steps to prevent another incident.

No other personal information was accessed, but the company warned customers to be alert for possible phishing emails or other follow-up scams using the exposed addresses.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)




文章来源: https://securityaffairs.com/200027/data-breach/japanese-railway-operators-keio-corporation-and-tokyo-metro-disclose-security-breaches.html
如有侵权请联系:admin#unsafe.sh