← Incident database

keio-ransomware-2026 · Disclosed 2026-09-26

Keio: ransomware on group servers

Ransomware on group servers affected some business systems; rail operations and information leakage were not reported as affected at disclosure.

Cause unresolved / undisclosed

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    Ransomware was confirmed early September 26 without affecting rail operations.

    [s1]1. 概要
  • Reported fact

    Entry cause and route are under external investigation; leakage was unconfirmed at publication.

    [s1]2. 現在の状況

Timeline

  1. Incident disclosed. [s1]

Reported response

  • Reported fact

    Keio reported disconnecting networks and starting an investigation to contain impact.

    [s1]2. 現在の状況

Evidence relevant to prevention

Insufficient evidence

The entry cause is unknown; inspect shared-system dependencies, containment procedures, and restorable backups.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence.

September 26 is detection, not an established intrusion start; cause, CVE, leakage, and full recovery scope remain unknown.

Sources

  1. [s1] 京王電鉄 · Primary source

    不正アクセスによるシステム障害の発生について ↗

    Published 2026-09-26 · Reviewed 2026-10-02