Keio Corporation confirmed that ransomware compromised servers across its group in the early hours of September 26, disrupting payment, reservation, and customer-service systems at several retail and hospitality businesses. Keio Plaza Hotel Tokyo payment functions may have been affected, while railway operations continued normally because train services operate on a separate system.
Keio isolated its network, notified police, and engaged external specialists to investigate the intrusion route, operational impact, and potential access to customer or business-partner information. The company had not confirmed a data leak or identified a responsible ransomware group at the time of reporting.

See attribution, scope, and your downstream exposure.
2 events from the most recent confirmed update back to the earliest known activity.
Keio Corporation suffered a ransomware attack in the early hours of September 26. It isolated its network, notified police, and began investigating the intrusion with external experts; hospitality, payment, reservation, and customer-service functions were disrupted, while railway operations were unaffected.
Tokyo Metro separately disclosed unauthorized system access that resulted in the acquisition of approximately 59,000 members' email addresses. It said the affected system contained only email addresses and that it had identified and closed the exploited weakness; no connection to the Keio incident was established.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourceteiss.co.uk
Open sourcekeio.co.jp
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.