Cybersecurity 4 min read

Ransomware Hit Tokyo Rail Operator Keio. Its Trains Kept Running.

Keio confirmed the attack on 26 September and cut off parts of its network. Business systems, including at a group hotel, were disrupted; whether data was taken is not yet known.

Kenji Tanaka
Developer Tools & Cloud Analyst
Published 30 Sep 2026, 11:00 PM (SGT)
Share:
Passengers seen through the window of a commuter train in Japan Passengers seen through the window of a commuter train in Japan Photo by strohmi on Pixabay
Advertisement

30 SEP 2026 — Keio Corporation, one of Tokyo's big private railway operators, says ransomware hit its group servers early on 26 September. Train service continued, but the company cut off parts of its network to contain the attack, and business systems at some group companies were disrupted. It has not yet established whether customer data was taken. Separately, Tokyo Metro disclosed a breach of its members' programme that exposed about 59,000 email addresses. No link between the two has been reported.

Keio's statement

In its notice, published the same day, Keio confirms a ransomware attack on group servers early on 26 September. The company reported the attack to police and is working with outside experts to learn how the attackers got in and what they reached.

The notice says business systems at some group companies were affected, and that no information leak has been confirmed so far. Railway operations were not affected. Keio says it immediately isolated parts of its network to stop the damage spreading and will publish new facts as they emerge.

26 SeptKeio confirms ransomware on group servers
0Train services disrupted, according to Keio
~59,000Tokyo Metro member email addresses exposed
No claimNo ransomware group had taken responsibility at the time of reporting

Where the disruption appeared

Keio's notice does not name the affected companies. The group runs hotels as well as trains, and the Keio Plaza Hotel Tokyo warned on its website of possible delays to some customer-facing services, BleepingComputer reports. Local media reported that payment systems were disrupted.

Keio runs about 85 kilometres of track and 69 stations, and its hospitality division has 25 hotels, according to the same report. No ransomware group had claimed the attack at the time of publication.

Tokyo Metro's separate breach

Tokyo Metro said an unauthorised third party had obtained the email addresses of about 59,000 members of its loyalty programme, Security Affairs reports. No other personal information was accessed, the company said, and it warned members to watch for phishing emails. It says it has closed the weakness that was used.

Advertisement

Why an email list matters

An exposed email list matters because it tells a scammer which people use a service. A fake message that appears to come from Tokyo Metro about the breach is the obvious next lure.

Why the trains kept running

Railway signalling and train control usually sit on networks kept apart from office and commercial systems. Keio has not described its own architecture, but its notice makes the same split: business systems disrupted, trains unaffected. Cutting off parts of the network quickly is what stops an attack on one side reaching the other.

The more important question for customers is what Keio has not yet said. It has not confirmed whether data from hotel guests or rail customers was copied before the network was cut, and says it will report as soon as it knows.

Advertisement
Kenji Tanaka
Developer Tools & Cloud Analyst

Kenji Tanaka covers developer tools, cloud platforms, DevOps, CI/CD, and software supply-chain topics for RECATOOLS.

View author profile → · Editorial policy

About this byline Kenji Tanaka is a RECATOOLS editorial persona for developer tools, cloud, DevOps, and software supply-chain coverage. Articles are produced and reviewed under RECATOOLS editorial supervision.

Corrections policy

Advertisement