Full Report
Keio Corporation (Keio), a major private railway operator in Japan, said its network was hit by a ransomware attack over the weekend, disrupting some of its business systems. [...]
Analysis Summary
# Incident Report: Ransomware Attack on Keio Corporation
## Executive Summary
Keio Corporation, a major Japanese private railway operator, suffered a ransomware attack that disrupted internal business and payment systems. While railway operations remained functional, the company’s hospitality division experienced service delays and system outages. Keio is currently investigating the extent of data theft involving customer and business partner information.
## Incident Details
- **Discovery Date:** September 26, 2026 (Early hours)
- **Incident Date:** September 26, 2026
- **Affected Organization:** Keio Corporation
- **Sector:** Transportation / Hospitality
- **Geography:** Japan
## Timeline of Events
### Initial Access
- **Date/Time:** Preceding September 26, 2026
- **Vector:** Under Investigation (Not publicly disclosed)
- **Details:** Attackers gained access to group servers, leading to a system failure detected in the early morning of Saturday, Sept 26.
### Lateral Movement
- **Details:** The threat actors moved from initial entry points to reach and encrypt group servers, specifically impacting the hospitality business and payment processing infrastructure.
### Data Exfiltration/Impact
- **Details:** Ransomware encrypted business systems. Potential unauthorized access to customer and business partner data is currently being assessed. Operational impact included disruptions to payment systems and hotel customer-facing services.
### Detection & Response
- **Detection:** Confirmed following system failures in the early hours of Sept 26.
- **Response:** The network was shut down manually to prevent further spread. The incident was reported to the police, and external cybersecurity experts were engaged for forensics.
## Attack Methodology
- **Initial Access:** Not disclosed (Under investigation).
- **Persistence:** Not disclosed.
- **Privilege Escalation:** Not disclosed.
- **Defense Evasion:** Not disclosed.
- **Credential Access:** Not disclosed.
- **Discovery:** System reconnaissance targeted business and payment servers.
- **Lateral Movement:** Movement within the corporate network to hospitality-related servers.
- **Collection:** Possible access to customer and partner databases.
- **Exfiltration:** Under investigation.
- **Impact:** Ransomware encryption; Data Encrypted for Impact (T1486).
## Impact Assessment
- **Financial:** Significant disruption to payment systems; potential recovery costs and loss of revenue in the hospitality sector.
- **Data Breach:** Under investigation; potential compromise of customer and partner info.
- **Operational:** Disruption of business systems and Keio Plaza Hotel Tokyo services; railway operations were unaffected.
- **Reputational:** Public disclosure required; potential impact on trust regarding customer data handling.
## Indicators of Compromise
- **Network indicators:** None disclosed in initial report.
- **File indicators:** None disclosed (Ransomware strain currently unidentified).
- **Behavioral indicators:** Abnormal system failures; unauthorized server access in early morning hours.
## Response Actions
- **Containment measures:** Immediate shutdown of the corporate network to isolate affected segments.
- **Eradication steps:** Investigation by external experts to identify the "attack route."
- **Recovery actions:** Ongoing assessment of server backups and restoration of payment systems.
## Lessons Learned
- **Segmented Infrastructure:** The isolation of railway operational technology (OT) from the corporate hospitality network prevented a total shutdown of transportation services.
- **Visibility:** Early morning detection indicates a need for 24/7 managed detection and response (MDR) to catch intrusions before encryption phases.
- **Coordinated Threats:** The concurrent attack on Tokyo Metro suggests that the Japanese transportation sector may be facing a period of heightened targeting by specific threat actors.
## Recommendations
- **Audit Third-Party Integrations:** Investigate if the entry point was through a shared hospitality/payment vendor.
- **Enhanced Monitoring:** Implement behavior-based detection to identify large-scale file encryption or data exfiltration attempts.
- **Zero Trust Architecture:** Ensure that business systems (hotels/retail) are strictly segmented from critical infrastructure (railway signaling/control).
- **Data Protection:** Ensure offline, immutable backups are tested and ready for restoration to minimize downtime during ransomware events.