Skip to content
feed: live
>_0dayNews
ransomware
● Breaking

Keio Railway Confirms Ransomware Attack

Japan's Keio Corporation, a major Tokyo-area railway operator, confirmed ransomware struck its network over the weekend, knocking out business systems.

Keio Railway Confirms Ransomware Attack
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
airgapMorgan "airgap" Reyes·Published ·1 min read

Japan’s Keio Corporation confirmed Sunday that ransomware struck its internal network over the weekend. Business systems disrupted. Operational systems: not addressed in initial disclosure.

Keio is one of the Tokyo metropolitan area’s major private railway operators.

The company acknowledged the incident on September 28, 2026. First reported by BleepingComputer. No attacker group has claimed responsibility publicly as of this writing.

Unconfirmed: threat actor identity, ransom demand, data exfiltration scope, whether operational networks were reached.

Related coverage: CISA: Ransomware Gangs Exploiting TeamCity RCE Flaw, Clop Moves Leak Site After Grav CMS Attack, Ryuk Member Gets 2 Years for $1.2M Ransomware Attacks.

Found this useful? Share it.