Skip to content

Build1 publisher2 min readPublished

Keio's trains kept running through a ransomware attack on its group servers

Keio Corporation shut its network after ransomware hit its group servers on September 26, disrupting payments and the business behind its 25 hotels. Its trains appear unaffected. Investigators have not yet traced the attack path, so it is still unknown whether a designed boundary kept rail out of reach.

The Engineer · Build desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Photograph accompanying Keio's trains kept running through a ransomware attack on its group servers
Photo: yomiuri.co.jp

What happened

  • Keio runs 85 km of track across 69 stations, employs more than 2,200 people and brings in about $2.6 billion a year.
  • Keio reported the attack to police and brought in outside experts to trace how the attackers got in.
  • The company is still checking whether customer or business partner information was accessed.
  • As of September 28, two days after detection, no ransomware group had claimed the attack.
  • No vendor patch or CVE has been named in connection with the intrusion.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • constraint Keio's running trains cannot yet be cited as proof that separating rail from commercial IT works, because the attackers may simply have chosen the hotels and payments.
  • decision Groups that run transit and hotels on one corporate network face Keio's choice at detection: shut everything and lose payments, or keep payments up and risk the spread.
  • exposure Hotel guests and partners whose records sat on the group servers stay exposed to a leak, and a listing would normally follow any claim within days to weeks.

"In the early hours of September 26, 2026, we confirmed a ransomware attack on our group's servers," Keio said in its statement [7]. For anyone who designs networks, the word to note is "group's." A dev.to write-up of the incident says Keio runs its regulated transit business and its consumer hospitality business on the same corporate network [17].

Keio responded with a full network shutdown [2]. The write-up calls this the costly but defensible call. It trades customer-facing uptime, payments included, for a hard stop on lateral movement, and it treats the payment disruption and service delays as the direct cost of that choice [12]. I think Keio chose correctly. The choice also means the outage shows where Keio cut the network as much as where the attackers reached. From outside, a payment system the attackers encrypted looks exactly like one its owner switched off.

The trains are harder to explain. Train operations do not appear to have been affected [4]. The write-up gives two possible reasons. Either the rail environment was out of reach by design, or the attackers went for the hotel and payment systems because those were the fastest route to pressure and payment [13]. It adds that hospitality networks are dense with payment terminals, booking platforms and guest data, and tend to have many third-party connections and shared vendor access [14]. Both explanations produce the same outage.

The argument for walling a group's business units off from each other needs one of two findings from the investigation. The first would be attackers reaching for rail and being stopped at a boundary. The second would be payments and hotels going down together because they sat on common servers that a boundary could have split. Keio has not published its architecture. It has also not said how the attackers got in, which ransomware family they used, or how long they were inside before encryption, and investigators are still tracing the path [8][13].

The timing fits a known pattern. According to the write-up, ransomware crews routinely start encryption late on Friday or early on Saturday, when security teams are thinner and a response takes longer to organize [11]. Keio found its intrusion in the early hours of a Saturday [1]. The write-up says Keio detected the attack within hours, and it took the whole network down during a weekend shift [20][2].

The write-up also says almost every major ransomware operation now steals data before encrypting it [15]. Keio has not confirmed exfiltration [19].

What to watch

  • Investigators' account of the attack path, showing whether the attackers tried to reach rail systems and were stopped at a boundary.
  • A claim by a ransomware group, or a leak site listing naming Keio.
  • Keio's finding on whether customer or business partner data was accessed.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories