Tokyo Rail and Transport Operators Hit by Cyber Attacks Over Weekend
Tokyo Metro, one of the busiest subway networks in the world, confirmed that an unauthorized third party accessed the email addresses of 59,000 members of its Metpo loyalty programme. The operator said it has identified the likely entry point and taken steps to prevent a repeat, but warned affected customers to be alert for follow-up phishing attempts using the stolen addresses.
A second operator, Keio Corporation, disclosed a ransomware attack on September 26 that disrupted sales systems at some group companies, including the Keio Plaza Hotel, which reported delays responding to customer inquiries. Keio disconnected affected systems from the internet and said police are investigating whether business or customer data was leaked, though no leak has been confirmed so far. Railway operations themselves were not affected.
Separately, car rental company Times Car reported that an unauthorized party accessed its website on September 25, compromising members' personal details including names, addresses, dates of birth, membership numbers and driver's licence information. It is not yet clear whether the three incidents are connected, but they highlight a concentrated wave of attacks against Japanese transport-related businesses within a short period.