Key takeaways

  • Tokyo Metro (東京メトロ), which runs most of Tokyo's subway network, said on September 27, 2026 that an unauthorized party accessed a server for its Metpo (メトポ) points service.
  • About 59,000 email addresses of members may have been viewed or taken. Tokyo Metro says the server held no other member information, but describes this as what it has confirmed "at this stage".
  • According to press reports, the access was found while investigating an email delivery problem on September 20, was confirmed on September 25, and appears to have come from overseas.
  • Train services are not affected. Tokyo Metro has identified and fixed the suspected entry point, and is still investigating the cause and scope.

What happened#

Metpo is the points program for Tokyo Metro's registered members. According to Tokyo Metro's notice:

  • A third party gained unauthorized access to Metpo member services, and about 59,000 email addresses may have been viewed or obtained.
  • The server that was accessed stored member email addresses to which Tokyo Metro had stopped sending mail because messages could not be delivered.
  • The server contained no member information other than email addresses.
  • Tokyo Metro has identified the suspected point of entry and put measures in place to prevent further unauthorized access.
  • It is still investigating the full scope and cause.

Press reports add:

Detail Source
A problem with Metpo's member email delivery occurred on September 20, and the unauthorized access was found while investigating it ANN
The access was confirmed on September 25 ANN
The access appears to have come from overseas (国外からと思われる) ANN
The server belonged to the company contracted to run the service ANN
Train operations are not affected ANN, NHK

Timeline#

Date (2026) Event
September 20 Problem with Metpo member email delivery. Investigation begins
September 25 Unauthorized access to the server confirmed
September 27 Tokyo Metro announces the incident

What we don't know yet#

Tokyo Metro has not said:

  • How the attacker got in, or when the access began
  • Whether the addresses were actually taken, or only possibly viewed
  • Why the accessed server held only undeliverable addresses, and whether other Metpo systems were reached
  • Whether the September 20 email delivery problem was caused by the attack
  • Whether it has reported the incident to the police or the Personal Information Protection Commission

Our analysis#

A narrow leak, for now, and an odd one#

On what Tokyo Metro has disclosed so far, this is a limited incident: one kind of data, email addresses, on one server. But the details raise questions.

  • "At this stage." The notice says Tokyo Metro has confirmed the access "at this stage" (現段階では). It leaves room for the scope to change as the investigation continues.
  • Why only this server? The server held only the addresses Tokyo Metro had stopped mailing because messages could not be delivered, something like a suppression list in an email delivery system. The notice does not explain why an attacker would reach that data and nothing else, or how that server connects to the rest of the Metpo systems.
  • Is the email problem related? According to press reports, the access was found while investigating a problem with member email delivery on September 20. Tokyo Metro has not said whether the attacker caused that problem.
  • 59,000 is not a small number for a list of undeliverable addresses alone.

None of this means more data was exposed. But it is worth waiting for Tokyo Metro's follow-up before treating this as a closed, minor case.

The timing of the notice is reasonable for a data exposure. Tokyo Metro went public a week after the first sign of trouble and two days after confirming the access. The Digital Agency, by comparison, announced its breach eleven weeks after detection.

The anti-phishing guidance is the useful part#

Leaked email addresses of a well-known brand's customers are exactly what phishing campaigns need. Tokyo Metro's notice does two things that help its members:

  • It names the exact address its follow-up messages will come from: i.metpo@tokyometro.jp.
  • It says it will not ask members to complete any procedure or visit an external website.

Any message that claims to be from Tokyo Metro about this incident and asks you to click a link or enter details is therefore suspect. That is simple, checkable advice, and more Japanese breach notices should include it.

Two Tokyo rail operators in one week#

This is the second incident at a major Tokyo rail operator in a week, after the ransomware attack on Keio. The two are not connected as far as anyone has said, and they are very different: ransomware disrupting group businesses at Keio, and email addresses exposed from a points service server at Tokyo Metro. In both cases, the trains kept running.

What this means for readers#

  • If you are a Metpo member, watch for a message from i.metpo@tokyometro.jp. Be suspicious of anything else that mentions this incident, especially messages with links or requests for login details.
  • If you are visiting Tokyo, the subway is running normally. This incident affects only the points program's email data.

Japanese terms at a glance#

Japanese Reading Meaning
東京メトロ(東京地下鉄株式会社) Tōkyō Metoro (Tōkyō Chikatetsu Kabushiki-gaisha) Tokyo Metro Co., Ltd.
メトポ Metopo Metpo, Tokyo Metro's points program
不正アクセス fusei akusesu Unauthorized access
閲覧または取得された可能性 etsuran mata wa shutoku sareta kanōsei "May have been viewed or obtained"
国外からと思われる kokugai kara to omowareru "Believed to be from overseas"

We will update this article when Tokyo Metro publishes more.