<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/japan-s-keio-confirms-ransomware-attack-disrupted-business-systems-2djasgemj" -->

---
title: Japan&#x27;s Keio confirms ransomware attack disrupted...
description: Keio Corporation, a major Japanese railway and hotel operator, confirmed a ransomware attack on its group servers discovered early on September 26, 2026, which...
canonical: https://daily.dev/posts/japan-s-keio-confirms-ransomware-attack-disrupted-business-systems-2djasgemj
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Japan&#x27;s Keio confirms ransomware attack disrupted business systems | daily.dev
og:description: Keio Corporation, a major Japanese railway and hotel operator, confirmed a ransomware attack on its group servers discovered early on September 26, 2026, which...
og:url: https://daily.dev/posts/japan-s-keio-confirms-ransomware-attack-disrupted-business-systems-2djasgemj
og:image: https://api.daily.dev/og/posts/2DjaSGemj.png
og:image:alt: Japan&#x27;s Keio confirms ransomware attack disrupted business systems
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Japan's Keio confirms ransomware attack disrupted business systems

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 3 min read · 0 upvotes · 0 comments

## Summary

Keio Corporation, a major Japanese railway and hotel operator, confirmed a ransomware attack on its group servers discovered early on September 26, 2026, which disrupted business systems and reportedly payment systems at its hospitality division, including Keio Plaza Hotel Tokyo. Train operations were unaffected. The company reported the incident to police and is investigating with external experts whether customer or partner data was accessed; no ransomware group has claimed responsibility yet. Separately, Tokyo Metro disclosed unauthorized access that exposed 59,000 member email addresses, though it is unclear whether the two incidents are linked.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/japans-keio-confirms-ransomware-attack-disrupted-business-systems>

## Questions this post answers

### What happened in the Keio ransomware attack?

Keio Corporation, a Japanese railway and hospitality operator, confirmed a ransomware attack on its group servers detected early on September 26, 2026. The attack disrupted business systems and payment systems on the hospitality side, including at Keio Plaza Hotel Tokyo, while train operations were unaffected. Keio reported the incident to police and is investigating with external experts.

_Security teams tracking ransomware incidents at critical infrastructure firms can follow developments like this on daily.dev._

### Is the Tokyo Metro data breach related to the Keio ransomware attack?

It remains unclear whether the two incidents are connected. Tokyo Metro disclosed a separate cyber incident over the same weekend in which attackers gained unauthorized access to systems and accessed 59,000 member email addresses; the company said only email addresses were exposed and the security weakness exploited has already been closed.

_Anyone weighing coordinated attack risk across transit operators can keep an eye on incident updates via daily.dev._

## Similar posts on daily.dev

- [Asahi admits ransomware may have spilled data on 2M people](https://daily.dev/posts/asahi-admits-ransomware-may-have-spilled-data-on-2m-people-cghd79cvb) · The Register · 0 upvotes · 0 comments
- [Japan's largest taxi operator shuts systems after cyberattack](https://daily.dev/posts/japan-s-largest-taxi-operator-shuts-systems-after-cyberattack-jvxa4yfvc) · BleepingComputer · 0 upvotes · 0 comments
- [The ultimate business resiliency test: Inside Kantsu’s ransomware response](https://daily.dev/posts/the-ultimate-business-resiliency-test-inside-kantsu-s-ransomware-response-lwbfb7qda) · CSO Online · 0 upvotes · 0 comments
- [Asahi admits personal data may have been slurped in breach](https://daily.dev/posts/asahi-admits-personal-data-may-have-been-slurped-in-breach-0b7kk2lqt) · The Register · 1 upvotes · 0 comments

---

Tags: [#ransomware](https://daily.dev/tags/ransomware), [#data-breach](https://daily.dev/tags/data-breach)

[View this post on daily.dev](https://daily.dev/posts/japan-s-keio-confirms-ransomware-attack-disrupted-business-systems-2djasgemj)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Japan's Keio confirms ransomware attack disrupted business systems","url":"https://daily.dev/posts/japan-s-keio-confirms-ransomware-attack-disrupted-business-systems-2djasgemj","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/japan-s-keio-confirms-ransomware-attack-disrupted-business-systems-2djasgemj"},"datePublished":"2026-09-28T21:00:04.314Z","dateModified":"2026-09-28T21:00:25.492Z","description":"Keio Corporation, a major Japanese railway and hotel operator, confirmed a ransomware attack on its group servers discovered early on September 26, 2026, which...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/335b9443c8aee5bea0955cb1a1edb120?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/335b9443c8aee5bea0955cb1a1edb120?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/japan-s-keio-confirms-ransomware-attack-disrupted-business-systems-2djasgemj","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"ransomware,data-breach","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"Japan's Keio confirms ransomware attack disrupted business systems"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/japan-s-keio-confirms-ransomware-attack-disrupted-business-systems-2djasgemj#faq","mainEntity":[{"@type":"Question","name":"What happened in the Keio ransomware attack?","acceptedAnswer":{"@type":"Answer","text":"Keio Corporation, a Japanese railway and hospitality operator, confirmed a ransomware attack on its group servers detected early on September 26, 2026. The attack disrupted business systems and payment systems on the hospitality side, including at Keio Plaza Hotel Tokyo, while train operations were unaffected. Keio reported the incident to police and is investigating with external experts. Security teams tracking ransomware incidents at critical infrastructure firms can follow developments like this on daily.dev."}},{"@type":"Question","name":"Is the Tokyo Metro data breach related to the Keio ransomware attack?","acceptedAnswer":{"@type":"Answer","text":"It remains unclear whether the two incidents are connected. Tokyo Metro disclosed a separate cyber incident over the same weekend in which attackers gained unauthorized access to systems and accessed 59,000 member email addresses; the company said only email addresses were exposed and the security weakness exploited has already been closed. Anyone weighing coordinated attack risk across transit operators can keep an eye on incident updates via daily.dev."}}]}
```

