KEIO Corporation, a major private railway operator in Tokyo, disclosed that it was hit by a ransomware attack over the weekend, leading to a system failure that affected several business systems. The company detected the incident on the morning of 26 September 2026 and subsequently shut down parts of its network to contain the damage.
An official notice stated that Keio was investigating the scope of the impact, including potential leakage of confidential business and customer information, though no evidence of data exfiltration had been found publicly at the time. Keio Plaza Hotel Tokyo, part of the Keio Group, also reported difficulties but said it had not confirmed any information leakage. Despite the disruption to internal systems, train services were reported as operating normally during the initial response.
Separately, Tokyo Metro announced on 27 September 2026 that an unauthorised third party had accessed the email addresses of about 59,000 customers enrolled in its Metpo loyalty programme. The operator said it had identified the suspected entry point and taken steps to prevent further incidents, and it warned customers to be vigilant for phishing or other follow-on scams using the exposed addresses. No other personal data was reported as accessed in the Tokyo Metro incident. Keio and Tokyo Metro both emphasised ongoing investigations and promised further updates as more information became available.