Keio Corporation
Incident posture
Linked entities
- Victim
- Keio Corporation
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
Keio Corporation confirmed a ransomware attack that caused a system failure in parts of its group infrastructure, disrupting some business systems at affiliated companies while train services continued to operate. The company detected the intrusion early, notified law enforcement and engaged external cybersecurity specialists to investigate, and it shut down affected network segments to contain the threat. Although no data breach has been confirmed, the company is reviewing whether confidential or customer information was accessed, stolen or encrypted, and it has not disclosed the ransomware variant, any ransom demand or responsibility claimed by the attackers. Further updates are promised as the investigation proceeds.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Keio Corporation detected a ransomware attack in the early hours of September 26, 2026. The company issued a public notice on September 26 confirming the incident. Keio stated that the attack caused a system failure within parts of its group infrastructure, disrupting certain business systems at affiliated companies. The railway operator emphasized that train services continued to operate and that no data breach had been confirmed. Upon detection, Keio notified law enforcement and engaged external cybersecurity specialists to investigate the breach. The specialists are assessing the affected systems and evaluating potential damage.
Keio is also reviewing whether any confidential business information or customer data may have been accessed, stolen, or encrypted. As of the notice, no information leakage has been confirmed, but the investigation remains ongoing. The attack targeted servers used by the corporate group, causing outages that affected “some group companies’ business systems.” Keio did not specify which systems were affected, the number of systems, or the initially compromised environment. The company confirmed that there were no disruptions to train operations and that operational technology and passenger rail services were not affected. To contain the attack, Keio immediately shut down parts of its network and implemented network isolation. Keio has not disclosed whether systems were encrypted, whether a ransom demand was received, or whether the attackers claimed responsibility, and no recovery timeline has been provided; the company said it will provide further updates as more information becomes available and apologized for the disruption and concern caused.
Sources
Sources available to members: 1 source.