Keio ransomware attack disrupts hotel systems as Tokyo Metro reports breach
The twin incidents underscore ongoing cyber risks for major transport-linked brands in Japan, even when trains keep running.
Japan’s Keio Corporation reported a ransomware attack against its group servers on September 26, 2026, forcing it to shut parts of its network and disrupting some business systems, primarily on the hotel side rather than rail operations. The company is working with external forensics specialists and police to determine the intrusion path, scope of damage, and whether customer or partner data was accessed. Local reports indicate that payment systems in Keio’s hospitality arm have been affected, and Keio Plaza Hotel Tokyo has warned customers of possible service delays. Over the same weekend, Tokyo Metro disclosed a separate cyber incident in which attackers accessed 59,000 member email addresses via a now-remediated security flaw. Authorities and the companies have not established whether the two Japanese railway operators were hit by the same threat actor or in a coordinated campaign.
Why it matters
The Keio attack shows how a hit on corporate systems can spill into hospitality and payments without touching rail operations, creating service friction for guests and uncertainty over data exposure. The Tokyo Metro breach, disclosed the same weekend, widens the impact to tens of thousands of member accounts and highlights that multiple large operators can be probed at once, even if investigators have not tied the incidents to a single group.
Signal or noise?
Does this story matter, or is it hype? Decide before you see what everyone else thinks.
Sources
- BleepingComputer