CSIDB logo
Incident

Nihon Kotsu

Incident posture

Attack window
Jul 2026
Location
Japan
Status
Unknown
CIA posture
Available to members
Updated
2026-08-26 19:31

Linked entities

Victim
Nihon Kotsu
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jul 2026
Discovered
Undetermined
Disclosed
Jul 2026
Resolved
Pending

Summary

Nihon Kotsu disclosed that attackers gained unauthorized access to its internal systems, deploying malware that forced the shutdown of its phone‑based taxi dispatch, Hire Web ordering and reservation management platforms, and parts of its internal network. The company, which operates close to 9,000 taxis and hire vehicles with a workforce of over 18,000 and annual revenue near $1 billion, said its separately operated GO app remained functional while its own booking channels stayed offline, prompting it to direct customers to the GO app, taxi stands or street hailing. The disruption also suspended its labor taxi service for pregnant women across several cities. After detecting the intrusion, the company isolated affected systems, enlisted external cybersecurity specialists to investigate the scope and origin, and confirmed no data leak had been verified, while warning customers to watch for fraudulent messages purporting to be from the company.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On July 11, 2026, in the early hours, unauthorized actors gained access to Nihon Kotsu’s internal networks and deployed malware that disrupted core operations. The intrusion was detected shortly after it began, prompting the company’s staff to isolate the affected systems to limit further spread. As a result, the phone‑based taxi dispatch service, the Hire Web ordering and reservation management platform, and parts of the internal network were taken offline. Nihon Kotsu publicly disclosed the incident on July 13, 2026, confirming that the breach involved unauthorized external access and a malware infection.

The outage affected the company’s primary booking channels, leaving customers unable to book rides through its phone line or web portal while the GO taxi app, operated separately, continued to function normally. Nihon Kotsu advised riders to use the GO app under the “Nihon Kotsu” label, or to rely on taxi stands and street hailing for transportation. The disruption also halted the specialized “labor taxi” service that assists pregnant women nearing childbirth in Tokyo, Musashino, Mitaka, Tachikawa, Yokohama and Saitama. With a fleet of approximately 8,558 taxis and over 2,000 chauffeur vehicles serving about 18,228 employees, the service interruption impacted a significant portion of the operator’s daily operations across the Kanto and Kansai regions.

Nihon Kotsu engaged external cybersecurity specialists to investigate the scope of the intrusion, trace its origin, and support system restoration efforts. The company stated that, as of the latest update, no data leak had been confirmed, but it continued to examine that possibility and pledged to issue further public updates and direct notices to affected customers if new findings emerged. It also warned customers to avoid opening attachments or clicking links in any suspicious messages purporting to be from Nihon Kotsu, noting the risk of related fraud attempts, while no hacking group or extortion operation had claimed responsibility and no threat actor had been identified by name.

Sources

Sources available to members: 1 source.

CSIDB