“Exercise particular caution” — that was Tokyo Metro’s instruction to customers after an unauthorized third party accessed the email addresses of 59,000 users of its Metpo loyalty scheme, the operator disclosed on September 27.
Tokyo Metro: Metpo loyalty addresses exposed
Tokyo Metro, which the company notes moves over seven million passengers each day on some of the capital’s busiest subway lines, said on September 27 that an unauthorized third party had gained access to email addresses for 59,000 Metpo members. The operator said it “has identified the suspected point of unauthorized access and taken measures to prevent a reoccurrence.”
Tokyo Metro reported that only email addresses were taken and no other personal data was confirmed as compromised. Even so, the company explicitly urged customers to “exercise particular caution” about possible follow-on phishing attempts — a direct acknowledgement that exposed email lists can be leveraged for targeted fraud even when other data are not revealed.
Keio Corporation: ransomware, network disconnects, and hotel impacts
Keio Corporation, which runs a popular line linking central Tokyo with western suburbs and outlying areas, disclosed a ransomware attack that struck on September 26. The company said police are investigating the incident “including whether any confidential business information or customer data has been leaked.”
Keio said it acted to contain the threat by disconnecting systems from the internet. The company reported that “disruptions have occurred in the sales systems of certain group companies.” It added that, while no data leakage has been confirmed at the time of its notice, the investigation is ongoing and “there is currently no impact on railway operations.”
One named business affected by the disruption was the company’s Keio Plaza Hotel. The hotel warned that it “may take longer than usual to receive a response to inquiries made through the contact form on our official website and through various reservation sites,” and that, depending on circumstances, “we may not be able to respond to all inquiries.”

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleTimes Car: website breach impacting millions of rental customers
Separately, car-rental operator Times Car announced on September 25 that an unauthorized third party accessed its website the same day and compromised personal information for members and former members. The firm said exposed information included names, home and email addresses, dates of birth, membership numbers, driver’s license information, identity verification documents, and more.
Times Car estimated as many as 6.6 million individuals could be affected, including current and former members and Times Business Service members. The company advised that “possible leaks of personal information may be misused in phishing emails and other fraudulent activities” and warned customers to be cautious of “suspicious emails, phone calls, SMS messages, etc., that impersonate our company.”
The company also stated: “Passwords are stored in a format that cannot be recovered, and there is no risk of customer accounts being misused using this information.” Times Car reinforced customer protections by telling users it will never request passwords or credit card information via email, SMS, or phone.
What this means for commuters, Keio Plaza Hotel customers, and Times Car members
- Commuters who use Tokyo Metro: the operator says railway services are unaffected, but those enrolled in Metpo should be alert for phishing attempts sent to the exposed email addresses.
- Keio Plaza Hotel guests and reservation holders: reservation and contact channels may be delayed because Keio disconnected affected systems to contain the ransomware, and inquiries may take longer or go unanswered depending on the evolving situation.
- Times Car members and former members: up to 6.6 million people were warned their personal records may have been exposed; Times Car emphasized that stored passwords cannot be recovered from the format used but advised customers to be wary of impersonation and fraudulent contact.
Clustered incidents and investigations are ongoing
It is unclear whether the Tokyo Metro and Keio incidents are connected; the report notes only that both occurred within the same weekend and that a third transport-sector incident — the Times Car breach — happened during the same period. Keio has involved police in its investigation; Tokyo Metro said it had identified the suspected point of unauthorized access and taken preventative measures; Times Car published a customer notice outlining the scope of exposed data and advising caution.
For now, all three operators report no interruption to core transport services. Tokyo Metro and Keio both stressed that passenger travel remains unaffected. Still, the events underscore the operational separation some companies adopt between customer-facing railway operations and sales or back-office systems that, when hit by cyber incidents, can ripple into customer service, reservations, and privacy exposure.
Original story: https://www.infosecurity-magazine.com/news/japanese-railway-operators-cyber/




