Japanese transportation giant Keio Corporation is investigating a ransomware attack that disrupted business systems across parts of its group, while its railway network continued operating normally.
Keio detected the attack in the early hours of September 26 after ransomware hit servers used by the group. The company responded by disconnecting network systems to prevent the intrusion from spreading and reported the incident to police.
The disruption extended beyond Keio’s core railway business. Some systems operated by group companies became unavailable, affecting services including hotel operations and payment processing.
Keio Plaza Hotel Tokyo warned customers that the incident could delay responses to inquiries and other services. Other reporting indicated that payment systems were also affected, leaving some Keio businesses unable to process credit card transactions normally.
Despite those problems, the cyberattack did not interfere with train operations. Keio’s railway services continued running, indicating that the systems responsible for operating trains were not disrupted by the affected corporate infrastructure.
Keio is one of Japan’s major private railway operators, but its business extends well beyond transportation. The wider group operates hotels and other commercial services, creating a larger technology environment in which a cyberattack can affect customers even when railway services remain operational. Whether the attackers also stole information is still being investigated.
Keio said it has not confirmed a data leak but is examining whether confidential business information or customer data was accessed during the intrusion. The company has not disclosed what information was stored on the affected systems or how many customers could potentially be involved.
The initial entry point also remains unknown. Keio said external specialists are helping determine how the ransomware reached its systems and assess the full extent of the damage.
No ransomware operation had publicly claimed responsibility for the attack at the time of the initial disclosures. There is also no confirmed information about a ransom demand or the specific ransomware strain used against the company.
The incident occurred during a period of heightened cyber disruption affecting Japanese transportation companies. Tokyo Metro separately disclosed unauthorized access to one of its systems over the same weekend, exposing approximately 59,000 member email addresses. There is currently no evidence establishing that the two incidents are connected.
Keio says it will release additional information if its investigation uncovers new facts. For now, railway operations remain unaffected, while the company continues restoring disrupted business services and determining whether the ransomware operators managed to take data before the attack was contained.