Skip to content

Security1 publisher2 min readPublished

Ransomware attack on Keio disrupts the Japanese rail group's hotel business

Keio Corporation confirmed a ransomware attack on its group servers on 26 September that disrupted the Japanese railway operator's 25-hotel business. Keio is still checking whether customer or partner data was accessed, and no ransomware group has claimed the attack.

The Watch · Security desk

Illustration accompanying Ransomware attack on Keio disrupts the Japanese rail group's hotel business

What happened

  • After a system failure in the early hours of Saturday, Keio shut down its network to prevent further damage.
  • Train operations appear to have been unaffected, according to BleepingComputer's reporting on the incident.
  • Local media reported that the attack disrupted Keio's payment systems.
  • Tokyo Metro disclosed a separate intrusion the same weekend in which attackers accessed 59,000 member email addresses.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Hotel guests and business partners are exposed to an unknown degree until Keio reports whether their information was accessed.
  • cost Containment by network shutdown puts the cost on hotel customers, who face delayed services until Keio brings its systems back.
  • constraint Only the impact is known, so other rail groups cannot yet cite Keio as proof that attackers enter through hotels or other side businesses; that needs Keio's route findings.

Keio's own statement describes a wider scope than the hotels. "In the early hours of September 26, 2026, we confirmed a ransomware attack on our group's servers. We have reported the incident to the police and are conducting an investigation into the attack's route and damage with the cooperation of external experts," the company said [6]. The hotel-only picture comes from BleepingComputer, which reported that the incident appears to have affected only the hospitality side of the business [7].

That split shows where the damage landed. It does not show where the attackers got in, or that they picked the hotel arm as an easier way into a railway group. Keio says it is still investigating the attack's route [6]. Its statement refers to group servers and does not separate rail systems from hotel systems [6].

The hospitality business is 25 hotels, run alongside 85 km of track and 69 stations [4]. The group has more than 2,200 employees and reported annual revenue of about $2.6 billion [5]. The Keio Plaza Hotel Tokyo has posted a notice warning of possible delays to some customer-facing services [8].

Keio has confirmed three things: the ransomware, the police report and the network shutdown after Saturday's failure [2][6]. The payment-system outage comes from local media reports [9]. Data theft and attribution are both unconfirmed [3][10].

Tokyo Metro's incident that weekend was a different kind of attack [11]. Tokyo Metro is the larger network, with nine subway lines over 195 km, 180 stations and about 7 million passengers a day [13]. The company said the breached systems held only email addresses and that it has found and closed the weakness the attackers used [14]. Keio is dealing with ransomware on group servers. Tokyo Metro described unauthorized access to member email addresses [11]. BleepingComputer said it is unclear whether the same threat actor hit both operators in a coordinated campaign [12].

What to watch

  • Keio's findings on the attack's route, which would show whether entry came through hotel systems or group-level infrastructure.
  • A ransomware group claiming Keio or publishing data, which would settle both attribution and whether customer or partner records left the network.
  • Any published actor or technique shared by the Keio and Tokyo Metro incidents.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories