-
Keio Corporation confirmed hackers hit its group servers with a ransomware attack on September 26, 2026.
-
The attack disrupted card payments at Keio Store, some bus counters, and Keio Presso Inn bookings.
-
No hacking group has claimed the attack yet, and Keio has not confirmed any stolen data.

Japan’s Keio Corporation runs trains, hotels, stores, and other businesses across Tokyo. The company just confirmed that hackers broke into its network. A ransomware attack hit some of its business systems over the weekend. Trains kept running, but several other services felt the impact right away.
Hackers Hit Keio’s Group Servers First
Keio detected the attack early on September 26, 2026. The company said the attack struck several of its group companies at once. Keio’s team isolated the affected network right away to stop the spread. The firm also reported the incident to local police immediately.
Outside cybersecurity experts now help Keio trace how the attackers got in. These experts also work to measure the full extent of the damage. According to Keio’s official notice, the company has not confirmed any information leak so far.
Keio still checks whether attackers stole customer or business records during the breach. The company has not named the hackers or the group behind the attack publicly. BleepingComputer reported that no ransomware group had claimed responsibility as of September 28.
Stores, Buses, and a Hotel Feel the Impact
The ransomware attack rippled across several parts of Keio’s business empire. Japanese outlet ITmedia reported that some Keio Store locations lost card and electronic payment services. Point-related services at these stores also stopped working for a while. Keio Presso Inn paused new hotel reservations because of the system trouble. It reported that some commuter pass counters could not accept card payments either.
Keio Plaza Hotel Tokyo said its own servers took a separate hit. Staff detected this ransomware attack on the same day, September 26. The hotel warned that replies to website and reservation questions might take longer than usual.
Some guest inquiries might not get an answer at all for now. Despite the trouble, the hotel said its actual daily operations continued as normal. Keio Plaza Hotel also confirmed that it has found no leaked information so far.
Trains Keep Running while Key Questions Remain
Despite all the disruption elsewhere, Keio’s railway operations continued without a single stop. BleepingComputer noted that the attack seemed to stay limited to business systems only. The systems that control train operations stayed separate from the affected servers. Japanese media outlets confirmed that railway services ran on schedule throughout the incident.
This case shows how one ransomware attack can hit different parts of a company. Japan is also taking broader steps to improve early threat detection, as outlined in our recently covered story, Japan’s approval of a new cybersecurity policy to detect cyber threats earlier.
Keio runs trains, hotels, stores, and other services under one large group. An attack on shared or connected systems can still disrupt many customer-facing operations. This happens even when the company’s main transport service stays completely safe.
Many important details about this attack remain unknown right now. Investigators have not named the specific ransomware tool used in the attack. Nobody has confirmed yet if the hackers managed to steal any data. Keio also has not said whether the attackers made any ransom demand. The company promised to share new details as soon as it verifies more facts, according to its official statement.
Keio’s response shows a pattern many companies now follow after an attack. First, they isolate affected systems fast to limit further damage. Then they bring in outside experts to investigate the full scope. They also loop in police early, rather than trying to handle everything alone. This approach helps protect customers while the company works out what really happened.
For now, riders can trust that their trains will run on time. Shoppers and hotel guests, however, may face longer waits for some services. Keio says it continues to work closely with investigators on every front. The company will likely release more updates once its internal review wraps up. Until then, questions about stolen data and the attackers’ identity stay open.