Keio Corporation has confirmed a ransomware intrusion detected in the early hours of September 26, 2026, that forced a network shutdown and disrupted some business systems. The operator says rail operations were unaffected, with impact concentrated on its hospitality business of 25 hotels. Investigators are still determining the intrusion route and whether customer or business partner information was accessed, while a separate breach at Tokyo Metro exposed 59,000 member email addresses.
How the attack unfolded
The company identified a system failure in the early hours of Saturday and subsequently confirmed ransomware on its group servers. As a containment measure, Keio shut down its network to limit further damage. The incident has been reported to the police, and the company is working with external experts to examine how the attackers gained access and what harm was caused.
No ransomware group had publicly claimed responsibility for the Keio intrusion at the time of reporting.
Impact limited to hospitality operations
Keio is a large Japanese railway operator with 85 km of track and 69 stations, plus a hospitality business of 25 hotels. The company has over 2,200 employees and a reported annual revenue of about $2.6 billion.
According to the company, the disruption appears confined to the hospitality side, with no effect on train operations. A notice on the Keio Plaza Hotel Tokyo website warned customers of possible delays to some customer-facing services. Local media outlets have reported that payment systems were disrupted.
The company said it is still investigating the full scope and whether any customer or business partner information was accessed.
Separate Tokyo Metro breach
Tokyo Metro separately disclosed a cyber incident over the same weekend in which attackers gained unauthorized access to its systems and accessed 59,000 member email addresses. Although both Keio and Tokyo Metro are Japanese railway operators, it is unclear if the organizations were targeted in a coordinated campaign by the same threat actor.
Tokyo Metro is a major transit operator that runs nine subway lines covering 195 km and 180 stations, carrying an average of 7 million passengers daily. The company said the breached systems contained only email addresses and that it has already identified and closed the security weakness the attackers used in this case.