Keio Railway Confirms Ransomware Attack
Japan's Keio Corporation, a major Tokyo-area railway operator, confirmed ransomware struck its network over the weekend, knocking out business systems.

Japan’s Keio Corporation confirmed Sunday that ransomware struck its internal network over the weekend. Business systems disrupted. Operational systems: not addressed in initial disclosure.
Keio is one of the Tokyo metropolitan area’s major private railway operators.
The company acknowledged the incident on September 28, 2026. First reported by BleepingComputer. No attacker group has claimed responsibility publicly as of this writing.
Unconfirmed: threat actor identity, ransom demand, data exfiltration scope, whether operational networks were reached.
Related coverage: CISA: Ransomware Gangs Exploiting TeamCity RCE Flaw, Clop Moves Leak Site After Grav CMS Attack, Ryuk Member Gets 2 Years for $1.2M Ransomware Attacks.
Found this useful? Share it.


