Ransomware hits Keio Corporation, disrupts hotel payment systems in Japan
Keio Corporation, a Japanese railway and hotel operator, confirmed a ransomware attack detected early Saturday that disrupted business systems, primarily affecting its hospitality division. The company shut down its network, reported the incident to police, and is investigating with external experts whether customer or partner data was accessed. Local media say the attack disrupted payment systems, while train operations appear unaffected.
GoKawiil's interpretation of the reporting above, not reported fact.
The incident adds to a string of cyberattacks on Japanese transit-linked firms, following Tokyo Metro's separate disclosure of unauthorized access exposing 59,000 email addresses over the same weekend. No ransomware group has yet claimed responsibility for the Keio attack, and it remains unclear whether the two incidents are connected, though the timing raises questions worth watching as investigators determine scope and attribution.
- Keio Corporation suffered a ransomware attack detected early Saturday, disrupting hospitality business systems including payments.
- Train operations were reportedly unaffected, and no ransomware group has claimed the attack.
- Tokyo Metro separately disclosed unauthorized access exposing 59,000 member emails the same weekend, though a link between the two incidents is unconfirmed.
Source: bleepingcomputer.com, 2026-09-28
Published there as: “Japan's Keio confirms ransomware attack disrupted business systems”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.