The Keio ransomware attack is a timely reminder that cyber incidents can disrupt customer service, payments, reservations, and other everyday business functions even when an organization keeps its most critical operations running. Keio Corporation confirmed that ransomware affected group servers and caused problems in some business systems. The company disconnected networks, notified police, and began an investigation with external experts.
What happened in the Keio ransomware attack
Keio Corporation said it confirmed a ransomware attack on group servers in the early hours of September 26, 2026. The Japanese transportation and hospitality group took network-disconnection measures to limit further damage.
Keio reported that some group companies were experiencing problems with business systems. The company said railway operations were not affected.
Keio Plaza Hotel Tokyo separately confirmed system difficulties related to the attack. The hotel warned that responses through its website contact form and reservation services could take longer than usual, while hotel operations continued.
What is confirmed
- Keio confirmed ransomware on servers used by the group.
- Some business systems at group companies were disrupted.
- Keio disconnected networks to contain the incident.
- The company reported the incident to police and engaged external specialists.
- Railway operations were not affected, according to Keio.
- Keio Plaza Hotel said its operations continued despite delays affecting some digital services.
What remains unverified
Keio said it was still investigating the attack path, full scope of damage, and possible exposure of confidential or customer information. As of its public notice, the company had not confirmed a data leak.
No publicly identified ransomware group had credibly claimed responsibility when the incident was reported. Keio has not disclosed the initial access method, ransom demand, malware family, or whether any payment was requested or made.
Who and what may be affected
The confirmed impact involves business systems used by parts of the Keio group. Customer-facing effects included possible delays in responses to inquiries and reservation-related requests. Keio said train service remained operational.
Customers should rely on official Keio notices for updates. Until the investigation is complete, messages claiming that customer data was stolen or demanding immediate action should be treated cautiously.
Why this ransomware incident matters to small businesses
Ransomware does not need to shut down an entire company to create serious operational problems. Losing access to reservations, billing, email, shared files, payment processing, or customer-support tools can quickly interrupt revenue and damage customer confidence.
The incident also shows the value of separating critical operations from ordinary business systems. Keio reported disruption in some systems while railway and hotel operations continued. Network segmentation and tested continuity procedures can help prevent one compromised environment from disabling every business function.
Practical ransomware defenses for small businesses
Identify the systems that keep revenue moving
List the applications, devices, accounts, and vendors required for sales, billing, payroll, reservations, customer communication, and service delivery. Set a recovery priority for each system before an incident occurs.
Maintain offline or protected backups
CISA recommends maintaining encrypted offline backups and regularly testing restoration. A backup should not be considered reliable until the business has successfully restored files and essential applications from it.
Separate critical systems
Use network segmentation and separate administrative accounts to limit lateral movement. Payment systems, backups, servers, employee workstations, guest Wi-Fi, and operational technology should not all share unrestricted access.
Protect remote and administrator access
Require multi-factor authentication for email, cloud services, remote access, and privileged accounts. Remove unused remote-management tools, close unnecessary internet-facing services, and limit administrator rights to staff who need them.
Patch exposed systems quickly
Prioritize updates for firewalls, VPN appliances, remote-access tools, file-transfer platforms, and other systems reachable from the internet. These products are frequent entry points for ransomware operators.
Prepare manual workarounds
Document how the business will accept orders, contact customers, process urgent payments, and communicate with employees if normal systems are unavailable. Keep essential phone numbers and procedures available offline.
Build an incident response contact list
Record contact information for the cybersecurity provider, backup vendor, cyber insurer, bank, legal counsel, and local FBI field office. Store a printed copy in case email and cloud accounts are inaccessible.
What to do if ransomware is detected
CISA advises organizations to isolate affected systems immediately. Disconnect compromised devices from the network, preserve evidence when possible, contact incident-response professionals, and avoid restoring data until the environment has been contained and cleaned.
Businesses should also assess whether sensitive information may have been accessed before encryption. Modern ransomware incidents often involve data theft as well as system disruption.