Multiple Japanese Transport and Travel Firms Hit by Cyberattacks
Share
A series of cyberattacks has targeted major transport and travel operators in Japan, involving ransomware and significant data breaches affecting millions of users.
Ransomware Strike on Keio Corporation
Keio Corporation disclosed that it was hit by a ransomware attack on 26 September. The company responded by disconnecting its systems from the internet to contain the threat while police investigate the extent of the incident.
The attack caused disruptions to the sales systems of several group companies, including the Keio Plaza Hotel. While the operator is still investigating whether confidential business information or customer data was leaked, it has confirmed that railway operations remain unaffected.
Tokyo Metro Reports Passenger Email Compromise
In a separate incident, Tokyo Metro reported that an unauthorised third party accessed the email addresses of approximately 59,000 passengers enrolled in its Metpo loyalty scheme. The operator announced the breach on 27 September.
Tokyo Metro stated it has identified the point of unauthorised access and implemented measures to prevent a recurrence. While the breach was limited to email addresses, the company has urged customers to exercise caution regarding potential follow-on phishing attempts.
Massive Breach at Times Car
The scale of the regional security incidents is underscored by a major breach at car-rental provider Times Car. The company announced that an unauthorised party gained access to its website on 25 September, potentially compromising the personal information of up to 6.6 million current and former members.
The exposed data includes names, home and email addresses, dates of birth, membership numbers, driver’s license information, and identity verification documents. Times Car noted that while sensitive identity documents were involved, customer passwords are stored in a non-recoverable format and are not considered at risk.
The firm has warned users to be wary of fraudulent communications, such as suspicious emails, SMS messages, or phone calls, that may impersonate the company to solicit passwords, authentication information, or credit card details.




Leave a Reply