Skip to content
Tech CEO Daily

Ransomware hits Japan’s Keio group, disrupting hotel bookings and store payments

The Tokyo rail operator says trains are running normally, but hotel reservations, retail card payments and bus ticket sales were affected.

TC

By Tech CEO Daily Staff, Newsroom

· 2 min read

A hotel reception desk with a computer screen showing an error
AI-generated image for illustration. Not a photograph of the events described.

The news

Keio Electric Railway, a major private railway operator in the Tokyo area that also runs hotel, retail and bus businesses, said it detected a ransomware attack on group servers in the early hours of September 26. The company reported the incident to police and cut external network connections to contain it.

The disruption landed on customer-facing subsidiaries. According to ITmedia, card and e-money payments and loyalty-point functions stopped working at some Keio Store supermarkets, the Keio Presso Inn hotel chain suspended new bookings, and credit card sales at some Keio Bus ticket counters were unavailable. Keio Plaza Hotel in Shinjuku said the hotel remained open but replies to website inquiries and reservation-site requests were delayed.

Railway operations were not affected. ITmedia reported that the train control servers run on a separate system. Keio Plaza Hotel said it had not confirmed any data leak but was investigating, with the parent company, police and outside specialists, how attackers got in and what may have been taken.

BleepingComputer reported on September 28 that it could not find a ransomware group claiming responsibility. The outlet also noted that Tokyo Metro separately disclosed unauthorised access affecting about 59,000 email addresses; whether the two incidents are connected is unclear.

The numbers

Attack detected
Sept 26, 2026 (early morning)
Group units affected (per ITmedia)
4

Why CEOs should care

Keio’s experience shows the value of separating operational technology from corporate IT: the trains kept running while shared business systems failed. Ask your team which revenue-critical services share infrastructure, and whether payment, booking and back-office systems for different business units could all go down from one intrusion.

It is also a reminder to test manual fallbacks. If card terminals and booking engines fail on a weekend, who decides whether stores stay open or reservations are taken by phone, and how is that communicated to customers?

What's next

Watch for a leak-site claim and any confirmation of customer data exposure, which would bring notification duties under Japan’s privacy law.

Sources

TC
Tech CEO Daily Staff

Newsroom

Reporting and analysis from the Tech CEO Daily newsroom. Each story is researched from primary sources — company announcements, regulatory filings and official advisories — and fact-checked before publication.

Spotted an error? Request a correction. Read our editorial standards and AI policy.

The Daily Brief

The technology briefing for people running businesses.

Weekdays at 6 a.m. ET. Free.

More in Cybersecurity