Two major railway operators in the Tokyo region disclosed cyber incidents over the weekend, both stating that passenger train operations were unaffected. Tokyo Metro, which carries more than seven million passengers a day on some of the capital's busiest lines, said in a 27 September statement that an unauthorised third party had accessed the email addresses of 59,000 passengers enrolled in its Metpo loyalty scheme; it identified the suspected point of access and took measures to prevent recurrence, and warned customers to be alert to follow-on phishing. Separately, Keio Corporation, which runs the line connecting central Tokyo to the western suburbs, confirmed a ransomware attack that struck on 26 September, isolated its network to contain it and reported the incident to police; disruptions affected the sales systems of certain group companies, including Keio Plaza Hotel, with the operator stating that no data leakage has been confirmed so far and that inquiries and reservations may take longer than usual. Keio operates 85 km of track and 69 stations with a separate hospitality business of 25 hotels, over 2,200 employees and reported annual revenue of about $2.6 billion. No ransomware group had publicly claimed the Keio intrusion at the time of reporting, and the weekend clustering points to the same operational-technology boundary pressure carried elsewhere in this week's corpus.
| Attribute | Detail |
|---|---|
| Sector | Transport |
| Date | 2026-09-30 |
| Source | Infosecurity Magazine |
| Reliability | Tier 3 |