Tokyo Metro reports possible data exposure
Tokyo Metro announced on the 27th that approximately 59,000 email addresses registered by members of its Metpo points service may have been exposed through unauthorized access. The company said it detected access by a third party believed to be located outside Japan and is continuing to investigate the incident.
Investigation began after an email delivery problem
According to Tokyo Metro, the investigation began after a malfunction occurred in Metpo’s email delivery service on September 20. During its review, the railway operator identified unauthorized access to a server connected with the service. The access is believed to have originated from overseas, although the company has not publicly identified the person or group involved.
The affected server stored email addresses for which messages from Tokyo Metro could not be delivered. These addresses had been placed on a distribution suspension list to prevent repeated delivery failures. Tokyo Metro said the server did not store other member information alongside the addresses.
Scope of impact remains unclear
At this stage, the company has not confirmed whether all of the approximately 59,000 addresses were actually removed or viewed by the unauthorized party. It is also investigating whether other member information may have been exposed, the extent of any resulting damage, and the precise cause of the intrusion.
Tokyo Metro has stopped email distribution to the affected addresses while it examines the situation. Members who use Metpo should remain alert for unexpected messages, particularly emails requesting passwords, payment information, verification codes, or access to other accounts. Users should avoid clicking suspicious links and should confirm any communication through official Tokyo Metro channels.
What is Metpo?
Metpo is Tokyo Metro’s customer points service, designed to provide benefits to users of the Tokyo subway network. Depending on the program and applicable campaigns, members can receive points linked to eligible journeys or other participating services. Such programs are increasingly important in Japan, where railway operators are expanding digital services and loyalty platforms alongside traditional ticketing systems.
For overseas residents and visitors who use Tokyo Metro, the incident highlights the importance of checking the contact details associated with Japanese transport, payment, and travel applications. Email addresses can be valuable to criminals even when passwords or financial data are not involved, as they may be used in targeted phishing campaigns or combined with information obtained in unrelated breaches.
Tokyo Metro continues review
The company’s announcement did not indicate that payment card details or travel records had been exposed. However, Tokyo Metro has not completed its investigation, and the possibility of additional exposure remains under review. Further information is expected as the operator confirms the systems involved and assesses whether affected members need to be contacted directly.
Tokyo Metro is one of Japan’s most widely used urban railway operators, serving millions of passengers across the capital. The case underscores the challenge facing major Japanese transport companies as they manage growing volumes of customer data through online membership and rewards services. Clear communication, prompt containment, and practical guidance for users will be important as the investigation proceeds.