Skip to content
RegionAsia-Pacific

MediumII Cyber Warfare & Critical Infrastructure28 September 2026, Monday

Ransomware hits Japan's Keio, disrupting payments while trains keep running

Keio, a major Tokyo railway and hotel operator, confirmed a ransomware attack on its group servers on the morning of 26 September. Train services were unaffected. As of 28 September, card payments at its supermarkets and hotels and for bus tickets were partly suspended.

Location: TOKYO

According to a BleepingComputer report on 28 September, Keio operates 85 km of railway, 69 stations and 25 hotels, with annual revenue of about 2.6 billion dollars. The company detected the attack early on 26 September, cut the network off from external connections and notified the police. ITmedia reported on 28 September that credit card and electronic money payments stopped at some Keio Store branches. Keio Presso Inn suspended new reservations, and card ticket sales were halted at Keio Bus counters.

As of 28 September, it could not be verified whether any data had been leaked, and no ransomware group had claimed the attack. According to BleepingComputer, Tokyo Metro also disclosed the same weekend that one of its servers had been accessed without authorisation. About 59,000 email addresses from its membership programme may have been compromised. It is unclear whether the two incidents involve the same attacker. The attack reached the group's commercial IT layer, not its operational technology such as train signalling and control systems.

Talay assessment

Bottom line

The attack did not reach railway operations, but it paralysed the transport group's retail and hotel arms. The breach at Tokyo Metro the same weekend suggests that Tokyo's transport companies are on a target list. The most likely path is a gradual restoration of payment systems within days and a ransomware group coming forward with a leak claim.

Likely effects

  • Japanese critical infrastructureNegative1–6 months

    The importance of separating transport groups' commercial IT networks from their operational networks is back on the agenda; regulatory pressure may increase.

  • Cyber insuranceNegative1–6 months

    As ransomware attacks on large Japanese companies continue, cyber insurance premiums and terms may tighten.

Possibilities, ranked

  1. 1
    Gradual recovery55%

    Payment and reservation systems come back within a few days, and any leak proves limited.

    Watch: Keio's statements on system restoration and data leakage

  2. 2
    Leak claim35%

    A ransomware group claims the attack and publishes customer or employee data.

    Watch: A Keio entry on ransomware groups' leak sites

  3. 3
    Common attacker10%

    The Keio and Tokyo Metro incidents turn out to be linked to the same actor.

    Watch: A joint statement from Japanese police or the national cyber security centre

Probabilities are calibrated judgement based on the sources, not measurement, and are revised as new information arrives. Not investment advice.

Market reaction

Indicators affected

  • Hotels affected (group)▼ 25 hotels
  • Tokyo Metro emails exposed▼ ~59,000

Sources

  1. BleepingComputer — Japan's Keio confirms ransomware attack disrupted business systems
  2. ITmedia NEWS — Ransomware attack on the Keio group affects Keio Store payments and hotel reservations