Keio Corporation in Japan Acknowledges Ransomware Attack Disrupting Operations

Keio Corporation in Japan Acknowledges Ransomware Attack Disrupting Operations

Keio Corporation, a prominent private railway operator in Japan, reported that its network experienced a ransomware attack over the weekend, leading to disruptions in several of its business systems.

After a system failure occurred early Saturday morning, the company confirmed the attack and took measures to shut down its network to mitigate further damage.

Keio is currently assessing the impact of the incident and investigating whether any customer or business partner data was compromised.

As a significant railway operator in Japan, Keio manages 85 kilometers of track and 69 stations, in addition to operating a hospitality division that includes 25 hotels. The company employs over 2,200 individuals and has an estimated annual revenue of around $2.6 billion.

“In the early hours of September 26, 2026, we confirmed a ransomware attack on our group’s servers. We have notified the police and are working with external experts to investigate the attack’s origin and extent of the damage,” stated Keio.

The incident seems to have primarily impacted the hospitality segment of Keio’s operations, leaving train services unaffected.

A separate notice on the Keio Plaza Hotel Tokyo website has alerted customers to potential delays in certain services.

Local news sources have indicated that the cyberattack has caused disruptions to the company’s payment systems.

As of this writing, BleepingComputer has not identified any ransomware group claiming responsibility for the attack on Keio.

BleepingComputer has reached out to the company for further details regarding the incident and will update this post with their response once received.

Additionally, Tokyo Metro has reported a cyber incident over the weekend, where attackers gained unauthorized access to its systems, compromising 59,000 member email addresses.

While both Keio and Tokyo Metro are railway operators in Japan, it remains uncertain whether the two organizations were targeted in a coordinated effort by the same threat actor.

Tokyo Metro operates nine subway lines spanning 195 kilometers and 180 stations, serving an average of 7 million passengers each day.

The company has stated that the compromised systems contained only email addresses and has already identified and rectified the security vulnerability exploited by the attackers.

Build your security blueprint for AI-powered attacks. Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on the implications of AI-speed attacks, what defenders should avoid, and how to validate, decide, fix, and re-validate at machine speed. Save your seat.

Source: Original article

Leave a Reply

Your email address will not be published. Required fields are marked *

Back To Top