Breach report
Japanese railway operator Keio confirms ransomware attack on group servers

AI-generated illustration by CyberShitty. Not a photograph or a document from the organisations named.
Keio says ransomware hit its group servers on 26 September 2026, disrupting some group companies' business systems. Trains kept running, and no data leak has been confirmed so far.
What happened
Keio Corporation, a major private railway operator in Japan, said it detected a ransomware attack on its group's servers in the early hours of 26 September 2026. Ransomware is malicious software that encrypts systems, usually followed by a demand for payment. Keio said it cut network connections to limit the damage, reported the incident to police and is investigating how the attackers got in with help from outside experts.
Keio Plaza Hotel Tokyo, part of the group, published its own notice the same day. It said some of its systems were affected and that replies to inquiries sent through its website contact form and booking sites may take longer than usual.
Confirmed vs. claimed
Confirmed by Keio: the ransomware attack, disruption to business systems at some group companies, and no impact on train operations. The hotel says its day-to-day operations are also unaffected.
Reported, not confirmed by Keio: BleepingComputer, citing local media, says payment systems were disrupted. Keio's notice does not mention payments.
Unknown: whether any customer, partner or business data was taken. Both Keio and the hotel say they have not confirmed a leak and are still investigating. When BleepingComputer published on 28 September, no ransomware group had claimed the attack.
Who is affected
So far the confirmed impact is disrupted systems, not exposed data. People who deal with Keio group businesses, including hotel guests, may face slower responses. Keio has not said which group companies were hit or how many people could be affected if data is found to have been taken.
What to do
- If you have booked or recently stayed at a Keio group hotel, including from India, check booking details directly with the hotel rather than through links in unexpected emails.
- Treat messages that cite this incident and ask for payment or card details with suspicion. Keio has not announced any customer notifications.
- Watch Keio's official news page for updates on whether data was accessed.
- If you later receive a notice, work through our checklist on what to do after a data breach notice.
Sources
More breaches in Japan
- Times Car (Park24) — 25 Sep 2026
- Reqrea (Tabiq hotel check-in) — 15 May 2026