Keio Electric has spent the weekend working through a ransomware intrusion that reached servers used across its group companies, while the systems that move its trains stayed on a separate architecture. The disclosure followed reporting by Yomiuri Shimbun on Sunday that hotel booking services and card payments at some group retail outlets had stopped working.
That split — corporate IT under attack, rail operations untouched — is the detail that matters most for how regulators and police will read the case. It is also the detail that is easiest to state and hardest to verify from outside the company.
What is confirmed
Three things are on the record. Servers belonging to the Keio group were encrypted by ransomware. Booking functions at the group's hotel business went offline. Card payment processing failed at some group retail stores.
A fourth point is confirmed only by omission: Keio Electric says train operations run on systems that are not connected to the affected servers, and nothing in the company's statement points to signalling, rolling-stock management, or station gate equipment.
What is not confirmed is longer. The entry point is unknown. Whether customer data left the network is unknown. The number of affected people is unknown. Neither the company nor police have said whether a ransom demand was made, and no figure should be assumed in either direction — Japanese operators under this kind of pressure have no obligation to disclose a demand, and disclosure practice varies.
Where the damage actually lands
Ransomware rarely stops where it starts. It lands where credentials and shared file servers put it, and in a group the size of Keio that means the unglamorous middle: reservation databases, point-of-sale back ends, internal accounting, and the flat internal networks that tie a hotel front desk to a station retail counter.
Hotel bookings and card terminals are exactly the kind of collateral a commuter notices. They are also the kind of collateral that generates a personal-data question within days, because both systems hold names, contact details, and payment-adjacent records.
The segmentation question
Keio Electric's central claim — that rail operations are separate — is the claim every transport operator in Japan has spent a decade building toward. Railway control systems are operational technology, not office IT. They live on isolated networks with their own protocols and their own vendors, and the reason they are isolated is that a commuter railway cannot be patched and rebooted during a Monday morning peak.
Segmentation is a design decision, not a proof. A clean boundary explains why trains kept running; it does not explain how far into the corporate side the intruders travelled before anyone noticed, or how long they had been resident. Those questions are answered in the incident report, not in the first statement.
Who holds the file
The immediate criminal file sits with the Metropolitan Police Department, which handles cybercrime cases inside Tokyo, with support from the National Police Agency's specialised cyber units when a case touches multiple prefectures or organised actors. The NPA has pushed hard in recent years for early reporting, on the argument that an operator who calls in the first hour gives investigators something to work with; an operator who calls in the second week usually does not.
On the administrative side, the Cabinet Office's cybersecurity centre tracks incidents affecting designated critical infrastructure. A group-level IT compromise at a rail operator sits in a grey zone: the trains are critical infrastructure, the hotel booking engine is not, and both belong to the same balance sheet.
If personal data turns out to be involved, a third desk opens. Under Japan's Act on the Protection of Personal Information, a leak likely to harm individual rights or interests must be reported to the Personal Information Protection Commission and to the affected individuals. That clock starts when the company becomes aware, not when it finishes its forensics.
Liability, in plain terms
Three tracks can run at once. Criminal: unauthorised access and damage to electromagnetic records are separate offences, and the perpetrators — not the victim — face them. Regulatory: the data-protection filing duty above, plus sector guidance for transport operators. Civil and corporate: customer claims if data was mishandled, and the directors' duty of care question that always follows a long-undetected intrusion.
Japan has no blanket ban on paying a ransom, but police guidance discourages it, and any payment touching sanctioned entities carries its own exposure. That is a decision for the board and its lawyers, and it is not one the public will learn about quickly.
What to watch this week
Three markers. Whether Keio Electric publishes a second, more specific statement naming affected systems rather than describing them generically. Whether the data-protection filing appears on the commission's disclosure list. And whether restoration is described as complete or as a workaround — a workaround means the underlying systems are still being rebuilt.
For now, the confirmed facts are narrow: group servers encrypted, hotel bookings and some card terminals down, trains running on a network the attackers did not reach. Everything else, including who got in and what they took, is still the investigators' file.
