Japanese Rail Operators Keio and Tokyo Metro Hit by Cyberattacks
Two major Japanese railway operators, **Keio Corporation** and **Tokyo Metro**, have reported separate cyber incidents over the weekend. **Keio** confirmed a ransomware attack disrupting its business systems, while **Tokyo Metro** disclosed unauthorized access leading to the exposure of 59,000 member email addresses.

### Keio Corporation Suffers Ransomware Attack
**Keio Corporation**, a prominent private railway operator in Japan, announced that its network was compromised by a ransomware attack. The incident, which occurred in the early hours of Saturday, September 26, 2026, led to the disruption of some of its business systems.
Upon detecting a system failure, **Keio** promptly confirmed the attack and initiated a network shutdown to contain further damage. The company is currently investigating the full extent of the impact, including whether any customer or business partner information was accessed by the attackers.
**Keio**, a substantial entity with 85 km of track, 69 stations, and a separate hospitality division operating 25 hotels, reported annual revenues of approximately $2.6 billion. Its extensive operations include over 2,200 employees.
"In the early hours of September 26, 2026, we confirmed a ransomware attack on our group's servers. We have reported the incident to the police and are conducting an investigation into the attack's route and damage with the cooperation of external experts," **Keio** stated in an official announcement.
Initial assessments suggest the ransomware attack primarily affected **Keio**'s hospitality business, with no reported impact on its critical train operations. The **Keio Plaza Hotel Tokyo** website has issued a warning about potential delays in some customer-facing services.
Local media outlets have further indicated that the cyberattack disrupted the firm's payment systems. As of now, no specific ransomware group has publicly claimed responsibility for the attack on **Keio**.
### Tokyo Metro Discloses Data Breach
In a separate incident, **Tokyo Metro**, another major Japanese transit operator, also disclosed a cyber incident over the weekend. Attackers gained unauthorized access to its systems, resulting in the exposure of 59,000 member email addresses.
**Tokyo Metro** operates nine subway lines, covering 195 km and 180 stations, and serves an average of 7 million passengers daily. The company confirmed that the breached systems contained only email addresses and has already identified and remediated the security vulnerability exploited by the attackers.
While both **Keio** and **Tokyo Metro** are key players in Japan's railway infrastructure, it remains unclear whether these incidents are linked or if the organizations were targeted as part of a coordinated campaign by the same threat actor.