30 SEP 2026 — Keio Corporation, one of Tokyo's big private railway operators, says ransomware hit its group servers early on 26 September. Train service continued, but the company cut off parts of its network to contain the attack, and business systems at some group companies were disrupted. It has not yet established whether customer data was taken. Separately, Tokyo Metro disclosed a breach of its members' programme that exposed about 59,000 email addresses. No link between the two has been reported.
Keio's statement
In its notice, published the same day, Keio confirms a ransomware attack on group servers early on 26 September. The company reported the attack to police and is working with outside experts to learn how the attackers got in and what they reached.
The notice says business systems at some group companies were affected, and that no information leak has been confirmed so far. Railway operations were not affected. Keio says it immediately isolated parts of its network to stop the damage spreading and will publish new facts as they emerge.
Where the disruption appeared
Keio's notice does not name the affected companies. The group runs hotels as well as trains, and the Keio Plaza Hotel Tokyo warned on its website of possible delays to some customer-facing services, BleepingComputer reports. Local media reported that payment systems were disrupted.
Keio runs about 85 kilometres of track and 69 stations, and its hospitality division has 25 hotels, according to the same report. No ransomware group had claimed the attack at the time of publication.
Tokyo Metro's separate breach
Tokyo Metro said an unauthorised third party had obtained the email addresses of about 59,000 members of its loyalty programme, Security Affairs reports. No other personal information was accessed, the company said, and it warned members to watch for phishing emails. It says it has closed the weakness that was used.
Why an email list matters
An exposed email list matters because it tells a scammer which people use a service. A fake message that appears to come from Tokyo Metro about the breach is the obvious next lure.
Why the trains kept running
Railway signalling and train control usually sit on networks kept apart from office and commercial systems. Keio has not described its own architecture, but its notice makes the same split: business systems disrupted, trains unaffected. Cutting off parts of the network quickly is what stops an attack on one side reaching the other.
The more important question for customers is what Keio has not yet said. It has not confirmed whether data from hotel guests or rail customers was copied before the network was cut, and says it will report as soon as it knows.