CSIDB logo
Incident

Keio Corporation

Incident posture

Attack window
Sep 2026
Location
Japan
Status
Unknown
CIA posture
Available to members
Updated
2026-09-29 16:20

Linked entities

Victim
Keio Corporation
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Keio Corporation confirmed a ransomware attack that caused a system failure in parts of its group infrastructure, disrupting some business systems at affiliated companies while train services continued to operate. The company detected the intrusion early, notified law enforcement and engaged external cybersecurity specialists to investigate, and it shut down affected network segments to contain the threat. Although no data breach has been confirmed, the company is reviewing whether confidential or customer information was accessed, stolen or encrypted, and it has not disclosed the ransomware variant, any ransom demand or responsibility claimed by the attackers. Further updates are promised as the investigation proceeds.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

Keio Corporation detected a ransomware attack in the early hours of September 26, 2026. The company issued a public notice on September 26 confirming the incident. Keio stated that the attack caused a system failure within parts of its group infrastructure, disrupting certain business systems at affiliated companies. The railway operator emphasized that train services continued to operate and that no data breach had been confirmed. Upon detection, Keio notified law enforcement and engaged external cybersecurity specialists to investigate the breach. The specialists are assessing the affected systems and evaluating potential damage.

Keio is also reviewing whether any confidential business information or customer data may have been accessed, stolen, or encrypted. As of the notice, no information leakage has been confirmed, but the investigation remains ongoing. The attack targeted servers used by the corporate group, causing outages that affected “some group companies’ business systems.” Keio did not specify which systems were affected, the number of systems, or the initially compromised environment. The company confirmed that there were no disruptions to train operations and that operational technology and passenger rail services were not affected. To contain the attack, Keio immediately shut down parts of its network and implemented network isolation. Keio has not disclosed whether systems were encrypted, whether a ransom demand was received, or whether the attackers claimed responsibility, and no recovery timeline has been provided; the company said it will provide further updates as more information becomes available and apologized for the disruption and concern caused.

Sources

Sources available to members: 1 source.

CSIDB