www.infosecurity-magazine.com 29 Sept 2026, 09:45 UTC

Tokyo Rail Operators Report Cyber Attacks as Phishing Fears Grow

Tokyo Rail Operators Report Cyber Attacks as Phishing Fears Grow
CyberSIXT Evidence Panel Source marked as original reporting

TWO major railway operators in the Tokyo region have disclosed cyber-attacks, although passenger services remain unaffected. Tokyo Metro said on 27 September that an unauthorised third party had accessed the email addresses of 59,000 passengers enrolled in its Metpo loyalty scheme. The operator said it had identified the suspected access point and taken steps to prevent a recurrence. No other information was reported as stolen, but customers were warned to be alert to possible follow-on phishing attempts.

Keio Corporation said a ransomware attack struck on 26 September. It disconnected affected systems from the internet and said police were investigating whether confidential business information or customer data had been exposed. Sales systems at some group companies were disrupted, including at the Keio Plaza Hotel, potentially delaying responses to website and reservation enquiries. Keio said there was no confirmed data leakage and no impact on railway operations. It is unclear whether the Tokyo Metro and Keio incidents are connected.

The disclosures followed a separate incident at car-rental company Times Car. The company said an unauthorised third party accessed its website on 25 September, potentially affecting up to 6.6 million current and former members, including Times Business Service members. Information that may have been exposed includes names, addresses, dates of birth, membership numbers, driving licence details and identity-verification documents.

Times Car warned that the information could be used for phishing and other fraud, while saying passwords were stored in an unrecoverable format and could not be used to compromise customer accounts.

View full article

Article by CyberSIXT