Ransomware Attack Disrupts Keio Group Services While Tokyo-Area Rail Operations Continue

September 28, 2026

Summary

Keio Group has confirmed a ransomware attack that caused system disruptions across several businesses. Keio railway services are continuing to operate normally, with no reported impact on train operations. Some Keio Store locations cannot process certain credit card or electronic-money payments, and loyalty points may also be unavailable. Keio Plaza Hotel warned that replies to online inquiries may be delayed or missed. Keio Presso Inn has temporarily stopped accepting new reservations. Keio Bus reported that credit card payments are unavailable at some commuter-pass sales counters. The company has notified police, isolated parts of its network and brought in outside cybersecurity experts. Read the full article for practical information for travelers, shoppers and foreign residents in Japan.

Keio Group reports cyberattack and system disruptions

Keio Electric Railway announced on September 26 that servers operated by the Keio Group had been targeted in a ransomware attack, causing system disruptions across parts of the group’s business network. The company said some operating systems used by group companies were affected, but emphasized that railway services were not disrupted.

The announcement is significant for residents and visitors in the Tokyo area because Keio is involved in a wide range of services beyond rail transport. The group operates railway lines serving western Tokyo and parts of Kanagawa, as well as department stores, supermarkets, hotels, buses and other businesses. Its transportation network is used daily by commuters, students and tourists traveling to destinations including Shinjuku, Hachioji, Takaosanguchi and the popular Mount Takao area.

Payments affected at Keio Store

Keio Store said on September 27 that some outlets were experiencing problems with payment and loyalty-program systems because of the wider system failure. At affected stores, customers might be unable to pay by credit card or electronic money. The company also said that the awarding or use of loyalty points could be unavailable.

Customers shopping at Keio Store locations may therefore need to carry an alternative payment method, such as cash or a different card, until services are restored. The company is expected to provide further updates as its systems are inspected and recovery work continues.

Hotel reservations and inquiries face delays

Keio Plaza Hotel announced on September 26 that its hotel servers had been affected by the ransomware incident. The hotel warned that replies to inquiries submitted through its official website contact form or through booking websites could be delayed or, in some cases, not sent.

Keio Presso Inn separately announced that it would temporarily stop accepting new reservations because of the system disruption. Guests with existing bookings or travelers attempting to make a reservation should check directly with the relevant hotel and allow additional time for responses. International visitors may also wish to keep confirmation emails and booking references available when contacting hotel staff.

Keio buses also report payment limitations

Keio Bus said that credit card payments were no longer available at some commuter-pass sales counters. This could affect passengers purchasing or renewing passes, particularly those who normally rely on cashless payment. The company’s notice highlights how a cyber incident affecting shared corporate infrastructure can reach customer-facing services well beyond the original server environment.

Investigation and containment measures underway

Keio Electric Railway said it detected the attack in the early hours of September 26 and reported the matter to police. To prevent the incident from spreading, the company disconnected parts of its network and took other protective measures. It is working with external cybersecurity specialists to investigate how the attack occurred and determine the extent of the damage.

At this stage, the company has not indicated that railway operations have been affected. The continued operation of Keio trains is particularly important in Japan, where railways form a central part of everyday mobility and depend on extensive digital systems for ticketing, scheduling, maintenance and customer communication. Keio has not publicly provided a final assessment of the incident, including whether information was accessed or removed. Further announcements will be needed as the investigation develops.

For customers, the most practical response is to monitor official Keio Group, store, hotel and bus notices, carry alternative payment options and avoid sending sensitive information through unverified channels. The incident also serves as a reminder that large Japanese transport groups often operate diverse businesses through interconnected systems, making rapid containment and transparent communication essential.