DKDKCISSPSearch
Ransomware

Japan's Keio confirms ransomware attack disrupted business systems

Keio Corporation (Keio), a major private railway operator in Japan, said its network was hit by a ransomware attack over the weekend, disrupting some of its business systems.

DKCISSP News DeskBleepingComputer29 Sept 2026, 2:26 am
Japan's Keio confirms ransomware attack disrupted business systems
Image courtesy of BleepingComputer. Original report
DKCISSP REPORT

Keio Corporation (Keio), a major private railway operator in Japan, said its network was hit by a ransomware attack over the weekend, disrupting some of its business systems.

Following a system failure in the early hours of Saturday, the company confirmed the attack and shut down its network to prevent additional damage.

The company said it is investigating the extent of the impact and whether the attackers accessed any customer or business partner information.

The company has over 2,200 employees and a reported annual revenue of about $2.6 billion.

“In the early hours of September 26, 2026, we confirmed a ransomware attack on our group's servers.

We have reported the incident to the police and are conducting an investigation into the attack's route and damage with the cooperation of external experts,” Keio says .

Keio is a large Japanese railway operator with 85 km of track and 69 stations, as well as a separate hospitality business of 25 hotels.

The incident appears to have affected only the hospitality side of Keio’s business, not train operations.

Local media outlets have reported that the cyberattack disrupted the firm's payment systems .

At the time of writing, BleepingComputer could not find a ransomware group claiming the attack on Keio.

ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

A separate announcement published on the company’s Keio Plaza Hotel Tokyo website is warning of possible delays on some customer-facing services.

Tokyo Metro has also disclosed a cyber incident over the weekend in which attackers gained unauthorized access to its systems and accessed 59,000 member email addresses.

BleepingComputer has contacted the company to request more information about the incident, and we will update this post with their response once it reaches us.

What happened

Keio Corporation (Keio), a major private railway operator in Japan, said its network was hit by a ransomware attack over the weekend, disrupting some of its business systems.

Following a system failure in the early hours of Saturday, the company confirmed the attack and shut down its network to prevent additional damage.

The company said it is investigating the extent of the impact and whether the attackers accessed any customer or business partner information.

What changed

The company has over 2,200 employees and a reported annual revenue of about $2.6 billion.

“In the early hours of September 26, 2026, we confirmed a ransomware attack on our group's servers.

We have reported the incident to the police and are conducting an investigation into the attack's route and damage with the cooperation of external experts,” Keio says .

Who is affected

Keio is a large Japanese railway operator with 85 km of track and 69 stations, as well as a separate hospitality business of 25 hotels.

The incident appears to have affected only the hospitality side of Keio’s business, not train operations.

Why it matters

Local media outlets have reported that the cyberattack disrupted the firm's payment systems .

At the time of writing, BleepingComputer could not find a ransomware group claiming the attack on Keio.

Technical details

ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

A separate announcement published on the company’s Keio Plaza Hotel Tokyo website is warning of possible delays on some customer-facing services.

Tokyo Metro has also disclosed a cyber incident over the weekend in which attackers gained unauthorized access to its systems and accessed 59,000 member email addresses.

Response

BleepingComputer has contacted the company to request more information about the incident, and we will update this post with their response once it reaches us.

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

What security teams should do

Although both Keio and Tokyo Metro are Japanese railway operators, it is unclear if the organizations were targeted in a coordinated campaign by the same threat actor.

Tokyo Metro is a major transit operator that runs nine subway lines covering 195 km and 180 stations, carrying an average of 7 million passengers daily .

What remains unknown

Although both Keio and Tokyo Metro are Japanese railway operators, it is unclear if the organizations were targeted in a coordinated campaign by the same threat actor.

Attribution

BleepingComputer: Keio Corporation (Keio), a major private railway operator in Japan, said its network was hit by a ransomware attack over the weekend, disrupting some of its business systems.

What to watch next

Watch for additional victim details, indicators of compromise and follow-on exploitation reports.

Watch for revised vendor guidance, fixed versions and mitigation updates.

MORE IN RANSOMWARE

More cybersecurity reporting

Police dismantle KillSec ransomware gang allegedly led by 16-year-oldBleepingComputer · 1 Oct 2026, 7:55 pmINC Ransomware Attack: Impact, Victims, Recovery | HuntressHuntress · 1 Oct 2026, 5:30 amShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacksBleepingComputer · 27 Sept 2026, 12:33 amShinyHunters hacked Clop leak site using Grav CMS path traversal flawBleepingComputer · 26 Sept 2026, 2:27 am