Full Report
ランサムウェア攻撃によるシステム障害に関するお知らせとお詫び「ニュース」では、京王電鉄に関するニュースリリースやおしらせ、京王グループのおすすめ情報をご覧いただけます。 2026年9月26日未明に、当社グループのサーバーへのランサムウェアによる攻撃を確認いたしました。現時点において、警察への通報等を行ったうえで、ランサムウェアによる攻撃の経路や被害に関する調査を外部専門家の協力を得て進めております。
Analysis Summary
# Incident Report: Keio Corporation Ransomware Attack
## Executive Summary
On September 26, 2026, Keio Corporation identified a system failure caused by a ransomware attack affecting its group servers. The incident has disrupted sales systems for certain group companies, though railway operations remain unaffected. The company is currently investigating the extent of potential data exfiltration and the specific entry point of the attackers with the assistance of external specialists.
## Incident Details
- **Discovery Date:** September 26, 2026 (Early morning)
- **Incident Date:** September 26, 2026
- **Affected Organization:** Keio Corporation (Keio Group)
- **Sector:** Transportation / Infrastructure
- **Geography:** Japan
## Timeline of Events
### Initial Access
- **Date/Time:** Pre-discovery (exact time unknown)
- **Vector:** Under investigation
- **Details:** The specific method of entry is currently being analyzed by external experts.
### Lateral Movement
- **Details:** Attackers successfully transitioned from initial access to group-wide servers, impacting multiple group company systems.
### Data Exfiltration/Impact
- **Impact:** System failure affecting sales/business systems of several group companies.
- **Status:** Potential leakage of confidential business information and customer data is currently under investigation; no definitive breach confirmed as of this report.
### Detection & Response
- **Discovery:** Early morning on September 26, 2026, when system failures were identified.
- **Response Actions:** Immediate isolation of affected networks to prevent further spread and notification to law enforcement.
## Attack Methodology
- **Initial Access:** Unknown (Under investigation)
- **Persistence:** Not disclosed
- **Privilege Escalation:** Not disclosed
- **Defense Evasion:** Not disclosed
- **Credential Access:** Not disclosed
- **Discovery:** Not disclosed
- **Lateral Movement:** Evidence suggests movement from initial entry point to group-wide server infrastructure.
- **Collection:** Under investigation for potential theft of customer and corporate data.
- **Exfiltration:** Under investigation.
- **Impact:** Data encryption/Inhibition of recovery (Ransomware) causing operational disruption to sales systems.
## Impact Assessment
- **Financial:** Unknown; potential costs related to recovery and lost sales revenue.
- **Data Breach:** Under investigation; potential risk to corporate secrets and customer PII.
- **Operational:** Disruption to group company sales systems. Railway operations (critical infrastructure) remain functional.
- **Reputational:** High; public apology issued following disruption to services.
## Indicators of Compromise
- **Network indicators:** None disclosed in the initial public statement.
- **File indicators:** Ransomware presence confirmed on group servers.
- **Behavioral indicators:** Abnormal system failures discovered in the early morning.
## Response Actions
- **Containment measures:** Immediate shutdown/isolation of affected network segments.
- **Eradication steps:** External security experts engaged for investigation and removal.
- **Recovery actions:** Ongoing investigation into impact scope; reporting to the police.
## Lessons Learned
- **Visibility:** Rapid detection in the early morning hours allowed for immediate containment actions, preventing the impact from reaching critical railway safety systems.
- **Segregation:** The ability to maintain railway operations despite a server-side ransomware attack suggests effective network segmentation between corporate/sales systems and operational technology (OT) systems.
## Recommendations
- **Enhance Endpoint Detection:** Ensure robust EDR (Endpoint Detection and Response) across all group company servers to catch lateral movement earlier.
- **Vulnerability Management:** Conduct a thorough audit of all internet-facing assets to identify the initial entry point (e.g., VPN vulnerabilities or Phishing).
- **Review Backup Integrity:** Ensure offline, immutable backups are tested and ready to restore disrupted sales systems.