Keio Corporation, a major private railway operator in Japan, has confirmed that a ransomware attack struck its network over the weekend, disrupting business systems tied to its hospitality operations. The company said it identified a system failure in the early hours of Saturday, September 26, 2026, and subsequently shut down its network to contain the damage.

In a statement, Keio said it has reported the incident to police and is working with external experts to investigate the attack’s entry point and the extent of the damage. The company is still determining whether attackers accessed customer or business partner information.

Keio operates 85 km of railway track and 69 stations, along with a hospitality division that includes 25 hotels. The company employs more than 2,200 people and reports annual revenue of roughly $2.6 billion. Based on available information, the attack appears to have affected only the hospitality side of the business, with train operations unaffected.

A separate notice posted on the Keio Plaza Hotel Tokyo website warned guests of possible delays to customer-facing services. Local media have reported that the attack disrupted the company’s payment systems. No ransomware group had publicly claimed responsibility for the attack at the time of reporting.

Second Japanese transit operator hit same weekend

The Keio incident comes as Tokyo Metro separately disclosed a cyber incident over the same weekend, in which attackers gained unauthorized access to systems and obtained roughly 59,000 member email addresses. Tokyo Metro said the breached systems contained only email addresses, and that it has identified and closed the security weakness used in the intrusion.

Tokyo Metro runs nine subway lines spanning 195 km and 180 stations, carrying an average of 7 million passengers daily. While both Keio and Tokyo Metro are Japanese railway operators hit in the same weekend, it remains unclear whether the two incidents were part of a coordinated campaign by the same threat actor.

Security teams at organizations with adjacent hospitality, payment, or membership systems should treat this as a reminder to review segmentation between operational and customer-facing environments, particularly where payment processing is involved.