Ransomware Attack Hits Japan’s Keio Corporation Group, Disrupting Card Payments at Retail Stores — BigGo Finance | #ransomware | #cybercrime


Keio Corporation announced on September 26 that servers at its group companies had been hit by a ransomware attack, causing system disruptions across several group businesses. The company detected the attack in the early hours of the same day and immediately notified police while implementing containment measures including network isolation. No data leaks have been confirmed at this time.

The impact extends across a wide range of the group’s businesses.

Company / BusinessImpact
Keio Corporation (railways)Confirmed attack on group servers. Train operations unaffected as they run on a separate system
Keio Store (supermarkets)Card and e-money payments, as well as loyalty point accrual, unavailable at some stores
Keio Plaza HotelConfirmed attack on its own servers. Delays in responding to inquiries; business operations unaffected
Keio Presso Inn (hotels)New reservations and email inquiries suspended
Keio BusCredit cards unusable at commuter pass sales counters

While train operations have not been affected, credit card payments remain unavailable at some of the group’s retail stores. Business systems have also experienced issues, with the impact spreading primarily across the group’s retail operations. The railway operations servers run on a separate system and have not been affected by the attack.

The company is working with external experts to investigate the attack vector, the extent of the damage, and whether any confidential information or customer data has been leaked. Keio said it will promptly disclose any new findings.

Ransomware incidents in Japan remain at elevated levels. According to the National Police Agency, there were 226 reported cases in 2025. Since surging to 230 cases in 2022, the annual figure has hovered around 200, and the first half of 2026 saw 123 cases—the highest half-year total on record.