Security

Keio confirms ransomware attack on group server as hotels and card payments stall, trains run

Tokyo rail and retail group Keio says a ransomware attack hit a group server, knocking out hotel bookings and card payments while trains kept running on separate systems.

T
By TechQuire Daily Staff TechQuire Daily Staff
September 27, 2026 / 7 min read

Keio Corporation, the Tokyo commuter rail operator whose businesses stretch from trains to hotels, department stores and real estate, confirmed that a ransomware attack struck a server belonging to the Keio group in the early hours of September 26, 2026. The company published a notice dated the same day and labeled the incident as ransomware in the title, rather than using vaguer terms such as system failure or unauthorized access. Business systems at some group companies were disrupted, and the company said it was still investigating the scope of the impact, including whether confidential business information and customer information had been leaked.

The disruption reached customers in concrete ways. Hotel reservation systems operated by group subsidiaries became unusable, and some retail stores could no longer process credit-card payments, forcing businesses to switch temporarily to alternative payment procedures. Trains, however, kept running. Keio said there was currently no impact on railway operations, because the servers of the railway operation system sit on a separate network from the group business systems that were hit.

Keio Electric Railway Co., Ltd. said it immediately took measures such as cutting off network connections to prevent the damage from spreading. It filed a report with the police and is investigating the attack route and the damage with the cooperation of outside experts, and it said it will promptly announce any new facts that become known. In the notice, the company apologized for the trouble and concern caused to many people and listed a public relations department contact number, 042-337-3106.

The incident lands inside a sustained national surge in ransomware. Japan's National Police Agency counted 123 ransomware cases in the first half of 2026, the highest half-year total since it began compiling the data in 2020, and the Keio case fits a pattern of attacks that strike commercial and back-office systems while leaving safety-critical infrastructure untouched. For a group that sells train tickets, hotel rooms and department store goods under one corporate roof, the separation between those two worlds is now the central question.

Key Facts

Keio's own notice, dated September 26, 2026, states that the company confirmed in the early hours of that day that a system failure had occurred due to a ransomware attack on a server belonging to the Keio group. The document sets out the chronology, the scope of impact, the response and a contact for inquiries, and it repeats that no fact of information leakage has currently been confirmed while the investigation continues.

The Yomiuri Shimbun reported on September 27 that reservation systems at hotels operated by subsidiaries became unusable and that some retail stores became unable to process credit-card payments. The same report said there was no impact on train operations because the servers of the railway operation system are on a separate network, and it noted that Keio Electric Railway declined to give details on whether a ransom was actually demanded, saying it would refrain from commenting on details.

Japan Cyber Watch reported on September 27 that news reports cite Kyodo News for the card-payment disruption and ANN for the hotel reservations, and that Keio says it has not confirmed any data leak. RUS Tourism News reported on September 27 that the attack has disrupted some commercial systems across the wider group, affecting hotel reservations and payment services even as trains continue running normally.

What Keio has not disclosed is its own kind of fact. The notice does not name the group companies or services involved, does not say which company owns the server, and does not say whether a ransom demand arrived. Hotels such as Keio Plaza Hotel and retail operations such as Keio Department Store and Keio Store are run by separate group companies, which is part of why the blast radius was described only in general terms.

The background numbers are stark. The National Police Agency confirmed 123 ransomware cases in the first half of 2026, up by seven cases from the same period a year earlier, after 226 cases across all of 2025. About 60 percent of the H1 2026 cases, or 79 incidents, hit small and medium-sized enterprises, while 31 struck large companies. Manufacturing absorbed 37 of the cases, the largest single category, and wholesale and retail followed with 15.

Analysis

The most important technical fact in this case is not the ransom but the boundary. Attackers reached a business server, and the operational consequence was a payment terminal that could not accept a card and a hotel desk that could not open a reservation. Keio's choice to call the event ransomware on the same day it confirmed the attack, instead of reaching for softer language, is a small but meaningful signal: the company knew what it was dealing with and chose to say so publicly.

The bigger picture here is that network segmentation works, and September 26 was a live test of it. Because payments and reservations failed while the trains kept running, the evidence indicates that Keio keeps its rail operating systems separated from its business IT, and that separation held under a real attack. Modern railway groups run passenger reservation, retail, hotel and back-office networks alongside safety-critical signalling and train-control systems, and the entire design premise is that a compromised office server cannot reach a train.

That is not a reason for comfort at group level. The failure mode here was commercial, and commercial systems are where the money and the customer records live. A hotel that cannot take a booking and a store that cannot take a card push customers toward alternative payment procedures and lose revenue in the meantime, all while the attacker holds an encrypted server. Determining whether files were copied can take considerably longer than restoring basic services, which is why Keio's statement that no leak has been confirmed should be read as a status, not a conclusion.

Ransomware incidents can involve both encryption of systems and theft of data, with attackers sometimes threatening to release information unless a ransom is paid. Keio's refusal to comment on the details of any demand, as reported by The Yomiuri Shimbun, leaves the most consequential questions open: what was on the server, who else could be affected, and whether the group will face a second wave of pressure from data exposure rather than downtime.

Why It Matters

Keio is more than a train operator, and that is exactly why this incident matters beyond Tokyo. Its group includes hotels, department stores, retail and real estate, so a cyberattack on railway-linked corporate systems can affect accommodation and retail services without stopping a single train. For travelers the practical impact is a booking that will not complete and a card that will not be accepted; for the group it is a reminder that the surface it must defend is the whole conglomerate, not just the tracks.

The national numbers place the Keio case inside a much wider trend. Tech Insider reported on September 10, citing The Japan Times and the National Police Agency, that Japan recorded 123 ransomware cases in the first half of 2026, the highest half-year total since the agency began compiling the data in 2020, up seven from the same period a year earlier. The NPA breakdown shows roughly 60 percent of incidents, 79 cases, hitting small and medium-sized enterprises, with manufacturing absorbing 37 cases and wholesale and retail 15.

Kyodo News separately described suspicious access attempts averaging 13,687 per monitored IP address per day, more than 4,000 higher than the same period a year earlier. Keio, with a market capitalization of about 2.9 billion dollars, or 453.1 billion yen, and 586,018,150 shares as of April 30, 2026, is not a small business, but it competes in a market where attackers are busy across every sector, and where retail and hospitality sit squarely in the target set.

Next Up

Keio says it will promptly announce any new facts that become known, and the open questions it has left are the ones to watch: whether confidential business information or customer data was taken, which group companies and services were affected, which company owns the server, and whether a ransom demand was received. The police investigation and the work of outside experts will run in parallel with the company's own recovery, and the group has said it will continue to investigate the leakage question specifically.

The near-term test is whether hotel reservations and card payments come back at group businesses and whether the segmentation that protected the trains holds as systems are reconnected. The longer test, for a country that recorded 123 ransomware cases in six months and 226 in all of 2025, is whether operators such as Keio treat September 26 as proof that their architecture got the important part right, or as a warning about everything else they own.

Tagged

Comments (0)

No comments yet. Be the first to share your thoughts.