“In the early hours of September 26, 2026, we confirmed a ransomware attack on our group's servers. We have reported the incident to the police and are conducting an investigation into the attack's route and damage with the cooperation of external experts,” Keio says.
Keio Corporation: timeline, scale, and immediate steps
Keio Corporation disclosed that a system failure in the early hours of Saturday prompted discovery of a ransomware attack on its group's servers. The company responded by shutting down its network "to prevent additional damage," and has reported the incident to the police while working with external experts to investigate the attack's route and the extent of damage.
Keio described itself in its disclosure as a major private railway operator with 85 km of track and 69 stations, alongside a separate hospitality business of 25 hotels. The company noted it has more than 2,200 employees and reported annual revenue of about $2.6 billion.
Operational impact: hospitality systems and customer-facing services
Keio said the incident appears to have affected only the hospitality side of its business and not train operations. A separate announcement on the Keio Plaza Hotel Tokyo website warned of possible delays on some customer-facing services. Local media outlets also reported that the cyberattack disrupted the firm's payment systems.
Keio's public statements make clear the company is still investigating whether attackers accessed any customer or business partner information; that determination had not been resolved at the time of the disclosures.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleClaims, attribution, and evidence of compromise
At the time of reporting, BleepingComputer could not find a ransomware group claiming responsibility for the Keio attack. BleepingComputer said it had contacted Keio for more information about the incident and would update its post when a response arrived. Keio's own statement confined public claims to the confirmation of a ransomware attack, the network shutdown, and the ongoing investigation with police and external experts.
Tokyo Metro: a separate weekend incident and contrasts in data exposure
Also over the weekend, Tokyo Metro disclosed a separate cyber incident in which attackers gained unauthorized access to its systems and accessed 59,000 member email addresses. Tokyo Metro runs nine subway lines covering 195 km and 180 stations and carries an average of 7 million passengers daily, the company noted.
Tokyo Metro said the breached systems contained only email addresses and that it had identified and closed the security weakness the attackers used. Although both Keio and Tokyo Metro are Japanese railway operators, the reports state it is unclear whether the organizations were targeted in a coordinated campaign by the same threat actor.
What this means for technologists, police, and hotel customers
- Technologists and security teams: Keio's statement that it is "conducting an investigation into the attack's route and damage with the cooperation of external experts" indicates incident response activity focused on containment, forensic analysis, and determining whether data was exfiltrated.
- Police and regulators: Keio has reported the incident to the police, a formal step that places law enforcement into the investigative picture and signals an expectation of an official inquiry alongside private-sector forensics.
- Hotel customers and payment processors: a company notice and local media reporting point to possible delays on customer-facing services and disruptions to payment systems at Keio's hospitality units, which may affect booking, check-in, and payment processing until systems are restored.
Two disclosed incidents over the same weekend — one involving ransomware on Keio's group servers and one involving unauthorized access to Tokyo Metro systems — leave a narrow but important set of facts: Keio shut down its network after confirming the ransomware attack on September 26, 2026; the company is investigating and has involved police and external experts; Tokyo Metro says only email addresses were exposed and that it has closed the weakness used. Whether customer or partner records were accessed in the Keio incident, and whether the events are related, remain open questions pending the results of ongoing investigations.
Source: BleepingComputer — Japan's Keio confirms ransomware attack disrupted business systems




