Keio Corporation (京王電鉄), the Tokyo railway and transport group that runs the Keio and Inokashira lines, said on September 26, 2026 that ransomware had hit servers belonging to the Keio Group. The attack caused system outages, and business systems at some group companies stopped working properly. The company says train services were not affected. Keio cut network connections to stop the spread, reported the incident to police, and brought in outside specialists. It is now checking whether confidential business information or customer data was stolen. In its first statement, Keio said it had found no evidence of a data leak so far. It has not named a ransomware group, disclosed a victim count, or said whether any data volume was taken. Both sources covering the Keio incident are secondary reports: a Japanese security news site that closely summarises Keio's official notice (S6), and an English-language aggregator (S1). They agree on every material point.
What Happened
Both sources give the same timeline:
- Early hours of September 26, 2026: Keio found ransomware on Keio Group servers. S6 points out that this is when Keio detected the attack, which may not be when the attackers first got in. Keio has not said when the intrusion started.
- Containment: Keio disconnected its network to stop the attack spreading (S6). S1 describes this as isolating the affected network environments.
- Response: Keio reported the attack to police and is working with outside experts to find out how the attackers got in and how much was affected (S1, S6).
- Public statement: Keio published its first notice on September 26 (S6).
Business impact. Business systems at "some group companies" are down or degraded. Keio has not said which companies or which functions are affected (S6). The Keio Group spans transport, real estate, hotels, construction and facilities, and retail and lifestyle services. S6 specifically warns that the official notice does not support any claim that a particular hotel, shop, bus, taxi or e-commerce service is affected.
Rail operations. Both sources say train services are running normally. S1 credits this to separation between railway infrastructure and the corporate systems that were hit. That is a reasonable inference, but Keio has not described its network architecture. Trains on the Keio Line also run through onto the Toei Shinjuku Line, and the two operators have recently started sharing passenger-facing services such as a joint lost-property system launched in August 2026 (S4). As of the first notice, nothing suggests that any shared passenger service was affected.
What Was Taken
Nothing has been confirmed as taken. Keio is investigating possible theft of confidential business information and customer data. As of September 26, it said it had not confirmed any leak (S6).
According to S6, Keio has not yet disclosed:
- the ransomware family or the group behind it
- how the attackers got in, or when
- how many servers or devices were encrypted
- whether there was a ransom demand
- whether data was stolen
- which group companies and systems were affected
- when systems are expected to be restored
S1 says its incident details come partly from "Dark Web Intelligence". It also says the confirmed facts are "considerably narrower than many ransomware reports circulating online." We have not seen any credible leak-site listing, record count or data volume for this incident, and no source here makes one. Treat any claim of a specific stolen dataset as unverified until Keio or a leak-site post with sample data confirms it.
Why It Matters
Japan's 2026 run of ransomware and access incidents. Keio is the latest in a series of Japanese organisations disclosing ransomware or unauthorised access this year. The sources show a pattern that defenders should expect here too:
- Meitetsu Kyosho (名鉄協商), part of the Meitetsu transport group, found ransomware traces from June 19. It detected suspicious access on June 23, confirmed that customer data was at risk on July 28, and only on August 27 said that MKP point-card members' names, addresses, birthdates, phone numbers, emails and passwords might have leaked. It has still not given a count of affected members (S2).
- Marutaka Kogyo (丸高興業) first reported encrypted file servers in March. Its July follow-up said "at least" 1.5GB may have leaked and that attackers had deleted some logs, so it could not rule out data theft (S7).
- Japan's Digital Agency disclosed a breach of its Government Solution Service through a VPN device. About 246,000 government-staff records may be exposed. It detected the breach on June 25 but did not disclose it until September 11 (S8).
The lesson: a first notice saying "no leak confirmed" often gets revised weeks or months later. Customers and partners of Keio Group companies should not treat the September 26 statement as final.
The containment appears to have worked. For transport operators, the key question is whether ransomware on corporate IT reaches operational systems. Based on current reporting, Keio's train operations stayed up while business systems went down. That supports investing in IT/OT separation. Keio has not published details, so this should not be read as confirmed proof of any specific control.
A group-wide attack surface. The affected servers belong to the Keio Group, not just the railway company. Conglomerates with shared IT services, shared directories or shared network links give attackers ways to reach many subsidiaries from one entry point. The Meitetsu Kyosho case (S2) shows the same thing: one ransomware incident spread across multiple services and client organisations.
The Attack Technique
Unknown. Keio has not disclosed how the attackers got in, and neither source names a technique, CVE or threat actor (S1, S6).
For context only, and not as attribution, other Japanese incidents in the same period show which entry points are being exploited:
- VPN appliances. Marutaka Kogyo confirmed attackers entered through a VPN device, created a rogue admin account, moved to multiple servers and then encrypted data (S7). The Digital Agency breach also began with a known vulnerability in a VPN device, followed by abuse of a maintenance account (S8).
- Credential phishing against SaaS admin accounts. A Japanese online retailer lost data on 136,464 customers after an employee entered their e-commerce platform staff login on a phishing site. The account had no two-factor authentication and a weak password (S3).
- Vulnerabilities in internet-facing application servers. Helpfeel's Gyazo service was breached through a remote-command-execution flaw in an upload server, exposing about 23.62 million user records (S5).
None of these is linked to Keio. They show where Japanese defenders should look first while waiting for Keio's root-cause findings.
What Organizations Should Do
- Check that operational systems can survive IT going down. Confirm that signalling, train control, ticketing and other critical operational systems keep running if the corporate network is disconnected or encrypted. Test this with a tabletop exercise that includes cutting the network, not just on paper.
- Patch and monitor VPN and remote-access devices. Apply fixes for known vulnerabilities quickly. Alert on new admin accounts, logins from unusual locations, and use of maintenance or vendor accounts outside approved windows (S7, S8).
- Split up shared group infrastructure. Limit trust between subsidiaries in shared Active Directory and network links, so a foothold in one group company cannot become domain-wide encryption.
- Protect logs from tampering. Send authentication, VPN and server logs to an immutable store outside the domain. Without them, investigators may be unable to say whether data was stolen, as happened at Marutaka Kogyo (S7).
- Require phishing-resistant MFA on every admin and SaaS account, including e-commerce and platform staff accounts that hold bulk customer data (S3).
- Plan for follow-up disclosures. Pre-draft customer and partner notices, and warn users now about phishing that impersonates the affected brand. If data was stolen, scam messages pretending to be from Keio Group companies are likely to follow.
Sources: Japan’s Keio Corporation Hit by Confirmed Ransomware Attack — Rail... | 名鉄協商、サイバー攻撃でMKPポイントカードの会員 個人情報漏えいのおそれ 氏名・住所・パスワードなど、対象件数は非公表セキュリティニ... | 不正アクセスによるお客様情報漏えいに関するお詫びとお知らせ | Seamless Lost & Found Service for Keio and Toei Subway Lines Launch... | 「Gyazo」への不正アクセスによる情報漏えいに関するお知らせとお詫び | 京王電鉄にランサムウェアによるサイバー攻撃 一部グループ会社の営業システムに障害、鉄道運行は影響なしセキュリティニュースのセキュリティ... | 丸高興業、VPN経由のランサムで1.5GB漏えいのおそれ——調査結果を公式が公表 – CHOTTO NEWS | Non-Zero-Day VPN Flaw Left Japan ‘s Government Shared Network Platf...