teiss – News – Ransomware attack disrupts payment systems at Japan’s Keio railway group | #ransomware | #cybercrime


Keio Corporation, a major private railway operator in Japan, confirmed that a ransomware attack hit servers across its group companies in the early hours of Sept. 26, disrupting payment and reservation systems at several of its retail and hospitality businesses while leaving train operations unaffected.

Keio said it detected the attack early Saturday and immediately notified police while isolating its network to contain the damage. The company said it is working with outside experts to investigate the attack’s route, the extent of the damage, and whether any confidential information or customer data was leaked; no data leaks have been confirmed. Keio said it will promptly disclose any new findings. As of this report, no ransomware group had publicly claimed responsibility for the attack.

Train operations were not affected because they run on a separate system, Keio said. But the disruption spread across several of the group’s other businesses: card and e-money payments and loyalty point accrual were unavailable at some Keio Store supermarket locations; Keio Plaza Hotel confirmed an attack on its own servers that delayed responses to inquiries, though its operations continued; Keio Presso Inn suspended new reservations and email inquiries; and credit cards became unusable at Keio Bus commuter pass sales counters. Local media reported that the attack disrupted the company’s payment systems more broadly.

Keio Corporation operates 85 kilometers of railway track and 69 stations, along with a hospitality business of 25 hotels, and employs more than 2,200 people with annual revenue of about $2.6 billion.

The Keio attack came the same weekend that Tokyo Metro disclosed a separate cyber incident in which attackers gained unauthorized access to its systems and obtained 59,000 members’ email addresses. Tokyo Metro said the breached systems contained only email addresses and that it had already identified and closed the security weakness the attackers used. It remains unclear whether the two Japanese railway operators were targeted by the same threat actor as part of a coordinated campaign.

According to reports, ransomware incidents in Japan have remained elevated in recent years. Japan’s National Police Agency reported 226 cases in 2025, and the first half of 2026 saw 123 cases, the highest half-year total on record. Small and medium-sized enterprises accounted for 63.3% of victimized organizations, and more than half of affected organizations spent over 10 million yen, about $63,000, on investigation and recovery. Among cases where the infection route was identified, VPN devices accounted for 66.3% and remote desktop services for 20.7%.



Click Here For The Original Source.

——————————————————–

..........

.

.