Key takeaways

  • Keio Corporation (京王電鉄), which runs one of Tokyo's major commuter rail networks along with retail, hotel and real estate businesses, confirmed a ransomware attack on a group server in the early hours of September 26, 2026.
  • Business systems at some group companies were disrupted. News reports say credit card payments stopped working at some Keio group stores and hotel reservations were affected.
  • Train services are running normally.
  • Keio says it has not confirmed any data leak, but is investigating whether confidential business information and customer information were taken. It has reported the attack to the police.

What happened#

Keio published a notice on September 26, the same day it confirmed the attack. According to the notice:

  • In the early hours of September 26, Keio confirmed a ransomware attack on a server belonging to the Keio group, which caused system failures.
  • It has reported the attack to the police and is investigating the attack route and the damage with outside experts.
  • It immediately took steps to stop the damage spreading, including cutting off network connections.
  • Business systems at some group companies have been disrupted. Train operations are not affected.
  • It has not confirmed any leak of information. It is investigating the scope of the impact, including whether confidential business information or customer information was taken.

What was affected#

Keio's notice does not name the group companies or services involved. News reports add:

Service Status Source
Credit card payments at some Keio group retail stores Not working Kyodo News
Hotel reservations Affected ANN
Keio train services Running normally Keio

Keio's businesses are split across many companies. The railway is run by Keio Corporation itself. Hotels such as the Keio Plaza Hotel and retail such as Keio Department Store and Keio Store are run by separate group companies.

The notice says the attack hit "a server of the Keio group", not which company owns it. It could belong to Keio Corporation itself, to a subsidiary, or to a system shared across the group. What Keio does say is that the disruption hit the business systems of some group companies.

What we don't know yet#

Keio has not said:

  • Whose server was attacked (Keio Corporation itself or a group company), or which stores and hotels are affected
  • How the attackers got in
  • Whether it has received a ransom demand, or which group is behind the attack
  • Whether any data was actually taken

As of September 27, we have not seen Keio listed on ransomware leak sites tracked by ransomware.live. Groups often post victims days or weeks after an attack, so this can change.

Our analysis#

Named as ransomware from the start#

Japanese companies often describe attacks in vague terms at first. Common phrases include "system failure" (システム障害), "unauthorized access" (不正アクセス) or "a large volume of access from outside". Keio's notice says "ransomware" in its title, on the same day it confirmed the attack. It also says plainly that it is checking whether confidential information and customer data were taken.

That clarity helps. Customers know what kind of risk they face, and other companies know what kind of attack to look for. The next test is the follow-up: whether Keio explains how the attackers got in and what data, if any, was taken.

The railway held, and that deserves credit#

Whether the compromised server belonged to Keio Corporation itself or to a group company, the result is the same: payments and reservations failed, and the trains kept running. That strongly suggests Keio keeps its rail operating systems separated from its business IT, and that the separation held under a real attack. For a railway that carries commuters into central Tokyo every day, that is exactly the outcome network segmentation is meant to deliver, and Keio deserves credit for it.

The disruption to group businesses is a familiar pattern. Recent ransomware attacks on Japanese companies have hit group and subsidiary systems that run everyday business: payments, reservations, ordering and logistics. Japan's National Police Agency counted 123 ransomware cases in the first half of 2026, the most for any six-month period since it began tracking the figure. See our overview of ransomware in Japan for the full police data.

What this means for readers#

  • If you are traveling in Tokyo, Keio trains are running normally. Some Keio group stores may not accept credit cards for now, so carry another way to pay.
  • If you have a booking at a Keio group hotel, check with the hotel directly if you need to make or change a reservation.
  • If you are a Keio group customer or business partner, watch for follow-up notices from Keio about whether any data was taken, and be wary of unexpected messages that mention Keio.

Japanese terms at a glance#

Japanese Reading Meaning
京王電鉄 Keiō Dentetsu Keio Corporation (Keio Electric Railway)
ランサムウェアによる攻撃 ransamuwea ni yoru kōgeki Ransomware attack
システム障害 shisutemu shōgai System failure
営業システム eigyō shisutemu Business (operational) systems
ネットワーク遮断措置 nettowāku shadan sochi Cutting off network connections
情報漏洩 jōhō rōei Data leak

We will update this article when Keio publishes more.