Tokyo Metro Investigates Possible Leak of 59,000 Metpo Member Email Addresses

September 28, 2026

Summary

Tokyo Metro says approximately 59,000 email addresses connected to its Metpo points service may have been exposed. The possible leak was discovered after an email delivery malfunction on September 20. The company identified unauthorized access believed to have come from outside Japan. The affected server stored addresses where Tokyo Metro emails could not be delivered. Tokyo Metro says other member information was not stored on that server, but it is still investigating whether additional data was accessed. Email distribution to the affected addresses has been suspended. Metpo members should be cautious of suspicious emails requesting passwords, payment details, or verification codes. Read the full report for background and advice for users in Japan.

Tokyo Metro reports possible data exposure

Tokyo Metro announced on the 27th that approximately 59,000 email addresses registered by members of its Metpo points service may have been exposed through unauthorized access. The company said it detected access by a third party believed to be located outside Japan and is continuing to investigate the incident.

Investigation began after an email delivery problem

According to Tokyo Metro, the investigation began after a malfunction occurred in Metpo’s email delivery service on September 20. During its review, the railway operator identified unauthorized access to a server connected with the service. The access is believed to have originated from overseas, although the company has not publicly identified the person or group involved.

The affected server stored email addresses for which messages from Tokyo Metro could not be delivered. These addresses had been placed on a distribution suspension list to prevent repeated delivery failures. Tokyo Metro said the server did not store other member information alongside the addresses.

Scope of impact remains unclear

At this stage, the company has not confirmed whether all of the approximately 59,000 addresses were actually removed or viewed by the unauthorized party. It is also investigating whether other member information may have been exposed, the extent of any resulting damage, and the precise cause of the intrusion.

Tokyo Metro has stopped email distribution to the affected addresses while it examines the situation. Members who use Metpo should remain alert for unexpected messages, particularly emails requesting passwords, payment information, verification codes, or access to other accounts. Users should avoid clicking suspicious links and should confirm any communication through official Tokyo Metro channels.

What is Metpo?

Metpo is Tokyo Metro’s customer points service, designed to provide benefits to users of the Tokyo subway network. Depending on the program and applicable campaigns, members can receive points linked to eligible journeys or other participating services. Such programs are increasingly important in Japan, where railway operators are expanding digital services and loyalty platforms alongside traditional ticketing systems.

For overseas residents and visitors who use Tokyo Metro, the incident highlights the importance of checking the contact details associated with Japanese transport, payment, and travel applications. Email addresses can be valuable to criminals even when passwords or financial data are not involved, as they may be used in targeted phishing campaigns or combined with information obtained in unrelated breaches.

Tokyo Metro continues review

The company’s announcement did not indicate that payment card details or travel records had been exposed. However, Tokyo Metro has not completed its investigation, and the possibility of additional exposure remains under review. Further information is expected as the operator confirms the systems involved and assesses whether affected members need to be contacted directly.

Tokyo Metro is one of Japan’s most widely used urban railway operators, serving millions of passengers across the capital. The case underscores the challenge facing major Japanese transport companies as they manage growing volumes of customer data through online membership and rewards services. Clear communication, prompt containment, and practical guidance for users will be important as the investigation proceeds.