Japanese Transport Sector Faces Weekend Cyberattacks
Tokyo Metro, Keio Railway, and Times Car report separate cyber incidents over the weekend, impacting passenger data and operational systems.

Major Japanese transportation entities experienced significant cyberattacks over the weekend, with Tokyo Metro and Keio Railway reporting incidents that affected passenger information and internal systems, respectively. While passenger operations for both railway operators remained unaffected, the breaches highlight a concerning trend in attacks targeting critical infrastructure.
Tokyo Metro, which serves millions of passengers daily, disclosed that an unauthorized third party accessed the email addresses of approximately 59,000 individuals subscribed to its Metpo loyalty program. The company stated it has identified the point of unauthorized access and implemented preventative measures. Although only email addresses were compromised, Tokyo Metro has urged its customers to be vigilant against potential phishing attempts that may arise from this data exposure.
Separately, Keio Corporation, operating a key line connecting central Tokyo to its western suburbs, confirmed a ransomware attack occurred on September 26. The company has taken swift action by disconnecting affected systems from the internet to contain the threat. While investigations are ongoing to determine the extent of any leaked confidential business or customer data, Keio has assured the public that railway operations have not been impacted. However, disruptions have been noted in the sales systems of certain group companies, including the Keio Plaza Hotel, potentially leading to longer response times for inquiries.
Adding to the disruption, car-rental company Times Car announced on September 25 that its website was accessed by an unauthorized party, resulting in the compromise of personal information for up to 6.6 million current and former members. The exposed data includes names, addresses, dates of birth, driver's license information, and identity verification documents. Times Car warned members about potential misuse of this data for phishing and fraudulent activities, advising them to be cautious of suspicious communications and to never share passwords or sensitive information.
It remains unclear if these three incidents are interconnected. However, the simultaneous attacks on different segments of Japan's transport sector underscore a growing vulnerability. The nature of the attacks—ranging from data breaches affecting customer loyalty programs to ransomware impacting internal operations and large-scale personal data compromises—suggests a multifaceted threat landscape.
Authorities are investigating the full scope of each incident, including the specific attack vectors and threat actors involved. The incidents serve as a stark reminder for organizations, particularly those in critical infrastructure and transportation, to bolster their cybersecurity defenses and incident response capabilities. The potential for follow-on attacks, such as phishing campaigns leveraging stolen data, necessitates heightened awareness among affected individuals.
While passenger services were not disrupted, the breaches raise concerns about the security of sensitive personal data held by transportation companies. The ongoing investigations will be crucial in understanding the full impact and in preventing future occurrences within Japan's vital transport networks.