P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Keio says trains ran, but customer forms went unreadable at least seven hours before it confirmed the attack

Keio Corporation said ransomware was confirmed in the early hours of 26 September and that trains were unaffected. Its later notices, and those of seven other group companies, show applications unreadable from 17:00 the day before and no restoration date.

By Parminder Kumar Sharma · · 12 min read

Editorial illustration for the briefing: Keio says trains ran, but customer forms went unreadable at least seven hours before it confirmed the attack

The forms stopped before the attack was confirmed

On 28 September, Keio Corporation told customers that anyone who applied for a group ticket, the Keio Liner private-room plan or its Keio Location Service by form or e-mail after 17:00 on Friday 25 September should apply again by telephone, because Keio cannot see those applications (Keio's notice, in Japanese). Its ransomware notice says the attack was confirmed in the early hours of Saturday 26 September. The early hours cannot begin before midnight, so the window of applications Keio asks customers to repeat opens at least seven hours before its confirmation of the attack. That is our arithmetic: 17:00 to 24:00.

What that does not establish is most of the story. It does not say when anyone got into the network, when any server was encrypted, or why 17:00 is the line. The time could mark the start of the intrusion, the last point at which a mail or form queue was intact, or the moment something was cut off. Keio does not say which, and nothing else I could read does either. What it does show is that the date on the press notice and the moment customers began to be affected are two different clocks.

The version most readers will have seen is shorter: a Japanese railway was hit by ransomware and the trains kept running. The second half is Keio's own statement, and it is the least useful half for anyone who does business with the group.

Which Keio this is, and how it was read

The notice comes from 京王電鉄株式会社, which Keio's own site and its hotel subsidiary's English page call Keio Corporation. It is the parent of a Tokyo-area railway group. Nikkei xtech lists five business lines: transport, property, hotels, construction and building services, and lifestyle services (my translation). It is not Keio University, a separate institution with a different name in Japanese (慶應, not 京王), and no source I read connects the two. If you match supplier names in a threat feed, a rule on the romanisation "Keio" will catch both.

Eight group companies, each describing its own failure

Keio's first notice names no company. It says the business systems of "some group companies" are affected (my translation of 一部グループ会社の営業システム). The picture came together over the next two days from each company's own site. I found notices from eight group companies, the parent included, and there may be more.

What each Keio group company's own notice says has stopped, and what it says continued. Sources: the companies' own notices, read 29 September 2026. Translations are ours.

Company and noticeStopped or unreadableSaid to continue
Keio Corporation, 26 and 28 SeptContact form entries. Group ticket, Keio Liner private room and Keio Location Service applications by form or e-mail after 17:00 on 25 Sept: phone only.Train operations: "no impact at present".
Keio Plaza Hotel, 26 SeptSome systems. Website form and booking-site inquiries may be slow or go unanswered.Hotel operations: no impact at this time.
Keio Plaza Hotel Sapporo, 28 SeptKeio Group Points. E-mail replies may be slow.Existing bookings and restaurants.
Keio Presso Inn, 26 to 28 SeptNew bookings. E-mail inquiries, including earlier ones. Self check-in machines, smart TV and Wi-Fi.Existing bookings honoured. Front-desk check-in, slower than usual.
Keio Department Store, 28 SeptCard payments and points at some floors since the morning of 26 Sept. All procedures at the Tomo-no-Kai customer-club counter.Not stated beyond "some floors".
Keio Store, 27 SeptKeio Points. Cards and e-money at some stores. Inquiry e-mail. Up-to-date website leaflets.Rakuten Points still work.
Keio Bus, 26 SeptCredit cards at commuter-pass counters.Cards at Keio line ticket machines.
Keio Real Estate, 26 SeptReplies to inquiries and repair arrangements are slower than usual.Not stated. The notice names no cause.
Timeline from Friday 25 to Tuesday 29 September 2026 in Japan time, one row per Keio group company, eight in all. Keio Corporation applications are unreadable from 17:00 Friday. Presso Inn adds failures at 09:10 and 23:00 Saturday and 15:00 Monday. Other companies report failures from Saturday, Sunday or Monday. No row shows a restoration date.
Drawn from each company's own notice, read on 29 September 2026, and Nikkei xtech of 28 September for the train statement.

Two things the table cannot show. First, scope by count: Keio's press office told Nikkei xtech on 28 September that the attack hit two places, the group's servers and Keio Plaza Hotel's servers. That is second-hand, it is the only count anyone has given, and it leaves open which companies sit on the group servers. Nikkei xtech adds that Keio is still checking the order in which the two were reached. Second, the Keio Real Estate notice does not mention ransomware. It is in the table because Nikkei xtech and the group's other notices place it inside this incident, and I have not confirmed that from the company itself.

Systems disrupted is not customers unaffected

Three comforting phrases carry the first notice. "System failure" is the label in the title, and it describes the servers, not what a customer lost. "Business systems of some group companies" covers, in the companies' own words, card payments, loyalty points, hotel bookings, commuter-pass sales, customer-club counters, repair arrangements and inbound e-mail. And "no impact on train operations at present" is true on Keio's word, and is the sentence most readers carry away, although the railway company's own notices of 28 September ask customers to phone instead of applying by form.

BleepingComputer's report adds a framing that the group's pages do not support: it says the incident "appears to have affected only the hospitality side" of Keio's business. The hotels are three of the eight companies. The department store, the supermarket chain, the bus company, the property company and Keio Corporation's own forms are the other five. Where the article and the companies disagree, this briefing follows the companies.

The pattern across them is not about ransomware in particular. Shared services failed together. Keio Points stopped at Keio Store, Kitchen Court and Matsumotokiyoshi stores (some excepted), while Rakuten Points, an outside scheme, kept working; points are also reported down at some department store floors and at the Sapporo hotel. Card payments failed at some stores and at the bus company's counters but not at the railway's ticket machines. Six of the eight describe trouble with inbound inquiries, from delayed replies to mail the company cannot read.

Keio says it isolated the network to stop the spread. It does not say which failures are encrypted servers and which are systems it switched off itself. That is inference territory, and from outside the two cannot be told apart. For a customer at a till it makes no difference. For a defender it does: isolation is a choice, so the manual fallback for whatever it takes down is something you can decide before the night you need it.

What kept most customers moving was manual fallback, and it is visible in the notices. Applications went to a telephone line at the railway's sales department. Presso Inn moved check-in and check-out to the front desk. Keio Store asked shoppers to keep receipts for purchases that earned no points, with the method for adding them to follow recovery. Whether these fallbacks were planned or improvised the notices do not say. A group that has decided in advance what runs by phone, paper and cash can cut a network and stay open. One that has not will cut it anyway.

The most transferable failure is the quietest one. Presso Inn says it cannot see inquiries sent before the failure, not only new ones. Keio Store says it cannot see inquiry e-mail. Keio Corporation says applications by form or e-mail cannot be confirmed. None of the notices says whether senders saw an error. If they did not, a customer who wrote on Friday evening to cancel, to complain or to ask for their data has a sent message and no reader, and the sender's side looks normal. An inbound channel that fails without telling the sender is easy to leave off a risk register.

What the record does not establish

What Keio's notices state and what they leave out. Sources: Keio Corporation, Keio Plaza Hotel and group company notices, 26 to 28 September 2026; Nikkei xtech for the two points attributed to Keio's press office.

QuestionOn the recordNot on the record
Who was hitKeio Corporation: "the group's servers". Keio Plaza Hotel: its own servers.Which companies share the group servers. The order of the two compromises, still being checked (Nikkei xtech).
WhenConfirmed in the early hours of 26 Sept. Applications unreadable from 17:00 on 25 Sept.A clock time for the confirmation. When access began. What 17:00 marks.
DataKeio cannot currently confirm any leak of business or customer information, and is investigating.Whether any data was taken. Not confirmed is not none.
RansomKeio's press office told Nikkei xtech at noon on 28 Sept that no demand was confirmed.Anything on a Keio page. Whether a demand has arrived since.
Who did itNothing in any Keio notice. BleepingComputer found no group claiming it when it wrote.Any claim I could read. One social-media aggregator post appeared in search and I could not open it.
Encryption"Ransomware attack" and "system failure".Which servers, and how many, were encrypted. The word does not appear in the ten notices from eight companies that I read.
RecoveryKeio Store, 27 Sept: recovery time undecided. Presso Inn: bookings suspended for the time being.A date from any company. No page read on 29 Sept reports recovery.

On a group claim: BleepingComputer says it could not find one when it published. I found none in anything I could read, and I could not open the one social-media aggregator post about Keio that turned up in search, so I cannot say what it says. If a group does claim Keio, treat the name as a label rather than a scope. The same affiliates work under several brands, as our briefing on Storm-2570 sets out, and a claim is an allegation by a party that wants leverage.

What a UK organisation with Japanese subsidiaries or suppliers should check

Take this with you

Checks, in the order worth doing

  • Convert the cut-off. 17:00 on Friday 25 September in Japan is 09:00 that morning in the UK. List anything your Japan staff, travel desk or suppliers sent to a Keio company by form or e-mail after that, and treat it as unreceived until someone confirms it by phone.
  • Ask your travel and events teams whether any booking, change or cancellation involves Keio Plaza Hotel in Tokyo or Sapporo, Keio Presso Inn, group tickets, the Keio Liner private room or Keio Location Service. Confirm each by phone, using contact details printed on Keio's own notices.
  • Brief travellers and staff in Tokyo. Presso Inn has no Wi-Fi or smart TV and check-in is at the front desk only. Keio Bus commuter-pass counters do not take credit cards, though Keio line ticket machines do. Cards and points are down at some department store floors, and Keio Points are down at Keio Store shops.
  • If you have given a Keio company personal data, such as guest lists or passport details for a booking, ask in writing which systems held it and when Keio expects to be able to say whether any left. Keio says it cannot currently confirm a leak, which is not the same as none. Record the date you learned of the incident, for your own breach assessment.
  • Expect scam messages that borrow the outage, such as a booking that needs re-confirming or a payment that failed. No source I read reports any yet, so this is an expectation, not a finding. Act only on contact details printed on Keio's own notices.
  • Watch the individual companies' pages, not just the parent's. Keio's first notice named none of them, and each company has updated on its own schedule. Presso Inn keeps a dated log.
  • Test your own version. With your inbound mail and web forms cut off, what does a sender see: an error, or a thank-you page? Try it in an exercise, and write down who reads the backlog afterwards.
  • List the shared services in your own group that would vanish together if you isolated one network, such as payments, loyalty, ticketing, mail and forms, and write down the manual fallback for each.

Method and interest

Every fact about the incident comes from the companies themselves or from Nikkei xtech quoting Keio's press office. The companies have a reputational and legal interest in cautious wording, and their notices are cautious: where they name a cause it is ransomware, none says the systems were encrypted, and none says data is safe. News outlets do not share that interest, but they are working from the same notices. Aggregator sites I looked at repeat BleepingComputer and add nothing I could check, so I did not use them.

The question that exposes the gap

Ask your own incident lead one question. If you cut your network off at two o'clock on a Saturday morning, which of your customers could still reach you on Monday, by which channel, and who would be reading what they sent?

Keio says its trains ran. Everything customers use to book, pay, ask and apply is what the group had to answer for on the day.

Key facts

Sources

  1. PrimaryNotice and apology on system failure due to ransomware attack, 26 September 2026, Japanese, read in full; source of the entity, the early-hours confirmation, the scope wording, and the leak and train statementsKeio Corporation (京王電鉄株式会社)accessed 2026-09-29
  2. PrimaryNotice of 28 September 2026 on group ticket, Keio Liner private room and Keio Location Service applications, Japanese; source of the 17:00 on 25 September cut-offKeio Corporation (京王電鉄株式会社)accessed 2026-09-29
  3. PrimaryNotice of 28 September 2026 on the contact form system failure, Japanese; source of the unreadable contact form entriesKeio Corporation (京王電鉄株式会社)accessed 2026-09-29
  4. PrimaryNotice and apology, 26 September 2026, English page, checked against the Japanese page; source of the hotel's scope and the statement that hotel operations continueKeio Plaza Hotel Co., Ltd.accessed 2026-09-29
  5. PrimaryNotice of 28 September 2026 on the Keio group system failure, Japanese; source of the Keio Group Points and e-mail reply factsKeio Plaza Hotel Sapporoaccessed 2026-09-29
  6. PrimarySystem failure notice with dated update log, 26 to 28 September 2026 (last update 28 September 15:00), Japanese; source of bookings, e-mail, self check-in and Wi-Fi factsKeio Presso Innaccessed 2026-09-29
  7. PrimarySystem failure notice, 27 September 2026, Japanese; source of the points, payments, inquiry e-mail and undecided recovery timeKeio Store Co., Ltd.accessed 2026-09-29
  8. PrimaryNotice on the Keio group system failure, 28 September 2026, Japanese; source of the card, points and customer-club counter factsKeio Department Store Co., Ltd.accessed 2026-09-29
  9. PrimaryNotice of 26 September 2026 on credit cards at commuter-pass counters, JapaneseKeio Dentetsu Bus Co., Ltd.accessed 2026-09-29
  10. PrimarySystem failure notice, 26 September 2026, Japanese; source of the slower replies and repair arrangementsKeio Real Estate Co., Ltd.accessed 2026-09-29
  11. Reported byReport of 28 September 2026 quoting Keio's press office: two servers hit, ransom demand not confirmed at noon, order of compromises under investigation; the only source for those pointsNikkei xtechaccessed 2026-09-29
  12. Reported byReport of 28 September 2026 (read through an Internet Archive capture); the pointer to this story, the source of the no-group-claim statement and of the hospitality-only framing this briefing does not followBleepingComputeraccessed 2026-09-29
  13. Reported byReport of 28 September 2026 that links each group company's notice; used to find the company pagesITmedia NEWSaccessed 2026-09-29

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

One email per briefing. Unsubscribe any time.