Rail operators face ransomware disruption and customer email exposure

Rail operators face ransomware disruption and customer email exposure. Cyber incidents disrupted one Japanese railway group and exposed customers at another.

This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Wednesday, September 30th, 2026.

Cyber incidents disrupted one Japanese railway group and exposed customers at another. Ransomware forced Keio Corporation to shut down parts of its network after business systems failed. Train services continued normally, but some group companies and a hotel experienced operational difficulties. Separately, an unauthorized party accessed about fifty nine thousand email addresses from Tokyo Metro’s loyalty program.

Keio had not found evidence of information leakage, but its investigation remained underway. Tokyo Metro said no other personal information was accessed and warned customers about possible phishing. For leaders, these events show how cyber incidents can affect supporting business operations even when transport services remain available. Defenders should separate operational systems, monitor identity access, and prepare manual processes for reservations, inquiries, and customer communications. The wider pattern is that resilience depends on the systems surrounding frontline operations as well as the operations themselves. Review segmentation and recovery plans for every customer-facing and administrative system supporting essential transport services.

For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.

Rail operators face ransomware disruption and customer email exposure
Broadcast by