535/69 Wednesday, September 30, 2026

Keio Corporation, a major private railway and hotel operator in Japan, confirmed that it was hit by a ransomware attack on the morning of September 26, 2026, prompting the company to shut down parts of its network to prevent further damage. Over the same weekend, Tokyo Metro, another major Japanese railway operator, also reported a separate cyber incident that resulted in the exposure of member email addresses. The two incidents highlight continued cyber threats targeting organizations that support nationally important infrastructure, although there is currently no confirmed evidence linking the two attacks to the same threat actor.
In Keio’s case, the impact was reportedly limited to its hotel and hospitality businesses, causing payment system disruptions and delays to some services. No impact on railway operation control systems has been identified. The company is working with law enforcement and external security specialists to investigate the attack path and determine whether customer or business partner data was accessed. No threat group has claimed responsibility so far. In the Tokyo Metro incident, attackers gained access to the system and obtained approximately 59,000 member email addresses. The organization stated that only email addresses were affected and that the security vulnerability used in the attack has already been remediated.
Users and affected parties should remain cautious of suspicious messages or emails, as exposed email addresses could be used in phishing attempts to steal additional personal information or trick recipients into clicking malicious links. Organizations and system administrators should use these incidents as a reminder to strengthen cybersecurity controls, particularly through network segmentation between general business systems and critical operational environments, which can help limit the spread of damage during an attack. Regular risk assessments, vulnerability management, and a well-prepared incident response plan should also be maintained to support effective response and system recovery in the event of similar attacks.
