Nihon Kotsu, Japan’s largest taxi operator, said unauthorized external access involving malware compromised parts of its internal environment, forcing the company to disconnect affected systems and suspend several services. The disruption hit taxi dispatch, telephone-based bookings, online hire-car reservations, reservation management, web booking, and some internal systems, leaving customers to rely on the GO taxi app, nearby taxi stands, or street hailing while restoration work continues.
The company said it has isolated parts of its network and brought in external cybersecurity specialists to investigate the cause, scope, and possible impact of the intrusion. Nihon Kotsu has not confirmed any data leak and said it is still assessing whether customer or partner information was exposed, with notifications to follow if necessary; it also warned customers to be alert for suspicious messages or links impersonating the company.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
Following the cyberattack, Nihon Kotsu warned customers to watch for fraudulent messages impersonating the company. The notice accompanied its ongoing response and restoration efforts after the malware-linked intrusion.
The company brought in external cybersecurity specialists to investigate the cause and scope of the attack, restore systems, and assess possible data exposure. Nihon Kotsu said no information leak had been confirmed so far and that affected individuals would be notified if necessary.
In response to the intrusion, Nihon Kotsu disconnected or isolated affected systems and parts of its internal network. The disruption temporarily impacted taxi dispatch, hire car reservations, web booking, telephone dispatch, reservation management, and some internal systems.
Nihon Kotsu disclosed that its internal systems were compromised through unauthorized external access involving malware on July 11, 2026. The incident affected the company's internal environment and triggered its incident response.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
7 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcescworld.com
Open sourcecybernews.com
Open sourcesecurityaffairs.com
Open sourceteiss.co.uk
Open sourcenihon-kotsu-taxi.jp
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.