A ransomware hit on the Keio group has knocked out hotel reservations and card payments, forcing travelers to scramble. Trains are still running, but the rest of the network is in chaos.
Guests at Keio hotels woke up on September 26 to find booking and payment systems dead. The Keio group, a major name in Japan's rail and hospitality world, had been hit by ransomware. Trains kept moving. Everything else stopped. The attack exposed just how fragile these connected travel systems can be.
Keio Railway spotted the breach in the early hours. The company quickly cut off parts of its network to stop the spread. Police, outside cybersecurity experts, and Keio's own teams jumped in. But the damage was already moving through hotel and retail branches. Keio's official notice said only some subsidiaries' business systems were hit. The main railway network stayed safe. That was possible because of strict network splits and isolation for safety-critical systems.
Hotel bookings and payments collapse
Travelers felt the pain right away. Online hotel bookings failed or became unreliable. Card payment systems broke down at several Keio companies. Some guests had to call hotels to check their reservations. Others switched to cash or other payment methods. The attack showed how one cyber event can hit many parts of a big group, even if trains keep running. Japanese media confirmed that payment terminals and booking sites were down. The railway itself was not. Keio's train network uses dedicated hardware firewalls and split VLANs. This setup follows industry best practices to keep core operations safe.
Railway operations stay safe
While hotels and shops struggled, Keio trains ran as usual. The company stressed that train operations, including signaling and control, are kept apart from business networks. For Tokyo commuters and visitors, nothing changed on Keio lines. No need to change travel plans. This setup matches cybersecurity rules from the Agenzia per la Cybersicurezza Nazionale (ACN). These rules call for strict network splits and real-time checks for critical infrastructure.
Keio promptly disconnected external connections during the night of September 26 to contain the ransomware incident-a standard containment measure in such scenarios.
Data breach risk still unclear
Keio has not said if any company or customer data leaked. The investigation is still on. The group is checking if attackers stole files as well as locking systems. Ransomware often means both system lockout and data theft. Criminals may threaten to leak stolen data if not paid. It usually takes longer to check for data leaks than to get basic services back. As of September 27, there were no official reports of ransom paid, full recovery, or proof of stolen data. This comes from Japanese press reviews and Keio's own updates.
Travel sector faces rising cyber threats
The Keio case shows how exposed modern travel groups are. Hotels, shops, and payment systems are tied closely to transport. One breach can break many services. Travelers get stuck, even if trains keep moving. The best advice for now: check bookings directly and watch out for fake emails or payment requests. Italian regulators like Garante Privacy have stressed the need for fast breach alerts and clear updates to users if data is at risk.
Recent cases show ransomware is getting smarter. Attackers now target not just data, but the systems that keep companies running. Keio's experience is a warning. In the digital age, the real threat is not just a stopped train. It's a frozen network that supports the whole trip. Cybersecurity now matters as much as physical safety for travel to work.