Keio Corporation confirmed a ransomware attack on its group servers detected in the early hours of September 26, 2026. The attack disrupted business systems, primarily in the hospitality division, including Keio Plaza Hotel Tokyo. Railway operations were unaffected because train systems run on separate, segregated networks. No ransomware group has claimed responsibility. In a separate incident that same weekend, Tokyo Metro disclosed that an unauthorized third party accessed 59,000 member email addresses.
The incident disrupted payment and business systems across Keio’s hospitality division, including Keio Plaza Hotel Tokyo. Train services kept running. That distinction, railway operations continuing while hotel and retail systems went down, is the detail that matters most in understanding both how the attack unfolded and why it didn’t become far worse.
What Keio Has Confirmed
Keio’s public statement is short and precise. “Keio Corporation confirmed in the early hours of September 26, 2026, that a system failure occurred due to a ransomware attack.” The company shut down its network immediately after detection, notified police, and engaged external cybersecurity experts to assess the scope.
The attack affected sales and business systems across several Keio Group companies. Keio Plaza Hotel Tokyo published its own service disruption notice confirming that payment functions were impacted. Keio Bus and Keio Presso Inn were also among the affected entities within the group.
The investigation focuses on whether confidential business information or customer data was accessed or exfiltrated during the attack. Keio has not confirmed a data leak, and no ransomware group had claimed responsibility as of September 29. If a group surfaces with a claim, it typically appears on a dark web extortion site within days to weeks of an attack; the absence of such a claim so far is notable, though not definitive.
Estimated downtime for affected systems is around seven days based on available reporting. Estimated financial impact, including payment disruption and recovery costs, is approximately $2.5 million.
Why Trains Kept Running: The OT/IT Separation
The fact that Keio’s railway operations were completely unaffected by ransomware that disrupted its hotel and retail systems is not luck. It’s architecture.
Modern railway operations rely on operational technology (OT): the systems that control trains, manage signaling, handle ticketing, and coordinate scheduling. Keio’s train systems sit on a separate network from the company’s corporate and business IT infrastructure. The ransomware that penetrated the business side had no pathway to the operational side.
This is exactly the type of network segmentation that cybersecurity frameworks require for critical infrastructure. When it works, as it did here, a ransomware attack that would shut down an ordinary business becomes a disruption limited to commercial and hospitality operations, rather than a public transport emergency.
The lesson from Keio mirrors what happened to Keio’s hospitality payment systems. The hotel and retail network had enough connectivity to support the ransomware’s spread. The railway didn’t. That architectural gap kept thousands of Tokyo commuters on schedule while Keio’s IT team worked through the weekend.
This pattern highlights why Japan’s government pushed through the Active Cyber Defense Law earlier this year, and why Fujitsu specifically targeted railway operators and critical infrastructure as the first customers for its new KELA-powered dark web monitoring and threat hunting service.
The Tokyo Metro Incident: Same Weekend, Different Attack
Keio wasn’t the only Japanese railway organization to report a security incident that weekend.
On September 27, Tokyo Metro, a separate operator, disclosed that an unauthorized third party had accessed approximately 59,000 member email addresses from its Metpo loyalty program. Tokyo Metro said it had identified and closed the entry point the attacker exploited.
Critically, this is a different type of incident from what hit Keio. Tokyo Metro experienced unauthorized data access; credentials or a vulnerability were used to read customer email records, but there’s no evidence of encryption or ransomware. The Keio attack involved actual ransomware deployment and system disruption.
No security researcher has confirmed a connection between the two incidents. The timing is unusual enough to warrant the question. Still, two Japanese railway operators experiencing security incidents in the same 48-hour window could reflect either coordinated targeting or the statistical reality that large transportation operators are consistently targeted regardless of each other.
A third weekend incident, involving Times Car, reportedly exposed data of up to 6.6 million people, though reporting on that breach remains thinner and it has received less attention than the Keio and Tokyo Metro incidents.
Japan’s Ransomware Moment
The Keio attack fits a pattern of ransomware groups targeting Japan’s large conglomerates, though Keio’s specific attacker remains unidentified.
In 2024, the Kadokawa media group was hit by BlackSuit ransomware in a high-profile incident that disrupted Niconico, Japan’s major video-sharing platform. That attack came through what investigators assessed was likely a phishing entry point, and BlackSuit (a Russian-linked group) publicly claimed responsibility.
No such claim has emerged for Keio yet. A ransomware group that encrypts a major conglomerate’s systems and steals data would typically want to publicize that fact to maximize pressure for payment. The absence of a public claim may mean the group is in direct private negotiation with Keio, or that they haven’t yet decided whether to surface the claim. It could also mean the attack was disrupted before full encryption or exfiltration was complete; Keio’s quick network shutdown on detection may have limited what the attackers could ultimately retrieve.
As we’ve covered in looking at how ransomware operators structure their extortion campaigns, the timing of a public claim is strategic. Rhysida’s attack on Berlin’s government similarly surfaced publicly weeks after the actual breach. Keio’s story may not be finished yet.
What Hotel Guests and Business Partners Should Know
Keio Plaza Hotel Tokyo is one of Tokyo’s most prominent accommodation options, a 47-story landmark in Shinjuku that handles significant international guest volume. The payment system disruption over the September 26 weekend would have affected guests checking in, checking out, or making purchases at the hotel.
Investigators are still determining whether the attack accessed customer data, names, reservation details, and payment card information. Keio’s statement says it is investigating whether confidential customer or business partner data was leaked. Until that determination is made, anyone who stayed at Keio Plaza Hotel Tokyo or transacted with Keio Group hospitality businesses around the September 26 weekend should watch their payment card statements closely.
The payment system disruption specifically means card transaction data was being processed through systems that were simultaneously under a ransomware attack. Whether attackers focused on encryption, data theft, or both is not yet confirmed. For payment card exposure specifically, card issuers can typically flag potential compromise if the hotel notifies them.
For anyone whose data may be in the investigation’s scope, our guide on what to do when your personal data may have been exposed covers practical response steps while investigations are ongoing.
This incident also relates to the supply chain monitoring challenge Keio’s partner businesses face; companies that share data with Keio Group across reservations, logistics, or retail channels are also within the investigation’s scope for potential data exposure.
Frequently Asked Questions
When did the Keio ransomware attack happen?
In the early hours of Saturday, September 26, 2026. Keio detected the attack and shut down its network the same morning.
Were trains affected?
No. Railway operations continued normally because train systems run on networks that are separate from the company’s business and hospitality IT infrastructure.
Which Keio services were disrupted?
Business and sales systems across the Keio Group, primarily in the hospitality division, including Keio Plaza Hotel Tokyo’s payment systems and other retail operations.
Has any ransomware group claimed responsibility?
No. As of September 29, 2026, no group had publicly claimed the attack.
Is this connected to the Tokyo Metro breach?
Unknown. Tokyo Metro disclosed a separate incident the same weekend involving 59,000 member email addresses. No confirmed connection between the two incidents has been established.
What should Keio hotel guests do?
Monitor payment card statements for unexpected charges. If Keio issues formal notification letters to affected guests, follow the guidance provided. Report any suspected fraudulent transactions to your card issuer immediately.