Ransomware attack disrupts systems at Japanese railway operator Keio

Japanese railway operator Keio Corporation confirmed (Translation here) that a ransomware attack hit its group servers on September 26, causing system disruptions across some of its businesses.

Keio immediately disconnected portions of its network and is working with police and external experts to investigate the attack. The ransomware disrupted business systems at some Keio Group companies, including hotel and payment services, although railway operations were not affected.

Keio said it has not confirmed that confidential company or customer information was leaked but is continuing to investigate the scope of the incident. The disclosure came the same weekend Tokyo Metro reported a separate cyber incident involving systems containing approximately 59,000 member email addresses. The operators have not indicated that the incidents are connected.

Denis Calderone, CTO, Suzu Labs:

“Keio’s train operations survived this ransomware and all indicators point to network isolation between the rail systems and the corporate network. The hotel reservations, supermarket card payments, bus ticketing, department store loyalty points all went down indicating at least some level of shared infrastructure. We’re intrigued that there were 3 different Japanese transportation related incidents (Tokyo Metro had 59,000 member email addresses compromised through a breached vendor server, and Times Car lost data on 6.6 million accounts including driver’s license images) just days before mandatory cyber incident reporting kicks in for critical infrastructure operators.

“Japan’s National Police Agency reported 123 ransomware incidents in the first half of 2026, the highest six-month count on record. Forescout data shows Japan has gone from the 28th most-attacked country by ransomware groups to 14th in just two years, with attacks rising 39% year over year. VPN appliances were the entry point in roughly 60% of those cases. On October 1, Japan’s Active Cyber Defense law takes effect, requiring 257 designated critical infrastructure operators across 15 sectors, including rail, to report cyber incidents promptly to the government. Keio just became the preview of what that reporting obligation looks like in practice.

“Every critical infrastructure operator should be asking which of their systems would pass the same test if ransomware or some other threats were to hit their corporate or production networks tomorrow. The new reporting law is a step in the right direction, but reporting an incident faster doesn’t prevent one. With VPN appliances as the dominant entry point, the fundamentals matter more than the regulation. You should ensure you patch internet-facing equipment aggressively, segment what actually needs to be isolated, and don’t assume that business systems adjacent to critical operations have earned the same level of protection. As the trends this year have been showing, the best practice right now requires you to reduce the attack surface as much as possible. Reduce what is exposed to ease your defensive efforts.”

Seemant Sehgal, Founder & CEO, BreachLock:

“Keio containing the impact to business systems and keeping railway operations running suggests the segmentation between corporate IT and operational technology held up under real conditions, which is not something every operator in this space can currently claim. The useful question for other transit and logistics companies watching this is whether their own segmentation would perform the same way if tested tomorrow.”

Ransomware can make any business stop dead in its tracks or severely impair it. Thus the best advice is to never let the bad guys in so that you don’t get pwned.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading