Infosecurity Magazine iconInfosecurity MagazineSep 29, 2026 ~5 min source read

Two Tokyo Railway Operators and a Car-Rental Firm Report Weekend Cyber Incidents

Tokyo Metro disclosed unauthorized access to 59,000 loyalty emails; Keio Corporation reported a ransomware strike that disrupted business systems but not train services; Times Car revealed a large customer data breach affecting up to 6.6 million people.

Share this story

Send the public story page.

Useful takeaways from this story.

Tokyo Metro operates some of the capital's busiest subway lines, carrying over seven million passengers each day.

"While we have not confirmed any data leakage at this time, we are continuing our investigation.

It said in a statement on September 27 that an unauthorized third party had accessed the email addresses of 59,000 passengers signed up to its Metpo loyalty scheme.

Three separate cybersecurity incidents affecting Japanese transport-related organisations were disclosed in late September. Tokyo Metro reported unauthorized access to email addresses for its Metpo loyalty scheme. Keio Corporation said a ransomware attack disrupted some business systems and affected its hotel subsidiary's customer contacts. Car-rental firm Times Car warned that an intruder accessed its website and exposed personal information for millions of members.

What happened — operator-by-operator

  • Date disclosed: statement on Sept 27.
  • Impact: email addresses of 59,000 Metpo loyalty scheme members were accessed by an unauthorized third party.
  • Company response: identified suspected point of unauthorized access and implemented measures to prevent recurrence. Only email addresses were confirmed taken. Customers were urged to be vigilant for phishing attempts.
  • Incident date: ransomware detected on Sept 26.
  • Investigation: police are investigating the incident, including whether any confidential business information or customer data leaked. Keio says it has not confirmed any data leakage to date.
  • Incident date: unauthorized website access on Sept 25.
  • Security detail: passwords are stored in a format the company says cannot be recovered, and it states there is no risk of accounts being misused using password data. The company warned customers about increased phishing attempts and reminded them the firm will never request passwords or credit card details by email, SMS, or phone.
  • Operational continuity: both railway operators reported no disruption to train services. The main operational impact reported so far relates to sales and customer contact systems.
  • Follow-on fraud and phishing: exposed contact details and identity documents increase the risk of targeted phishing, impersonation, and other social-engineering attacks. Companies involved issued alerts urging caution.
  • Unclear connections: there is no confirmed evidence tying these three incidents together.

Concrete steps for affected customers

  • If you are a Times Car member, follow the company's official guidance and check which personal fields may have been exposed.
  • Change reused passwords and enable multi-factor authentication on accounts where available.

More context around this story.

Укрзалізниця попередила про затримки поїздів через атаки на залізницю
Unn iconUnnSep 13, 2026

Укрзалізниця попередила про затримки поїздів через атаки на залізницю

Укрзалізниця попередила про затримки поїздів через атаки на залізницю <p>Через системні атаки рф залізниця змінює маршрути та евакуює пасажирів. Затримки виникли на напрямках до Варшави, Дніпра й Запоріжжя.</p>

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app