Primary: Keio Electric Railway notice nr260926v13404 (Sep 26). The company said it confirmed a ransomware attack on group servers in the early hours of Sep 26, notified police, engaged external specialists, and took network isolation / containment steps. Some group companies’ business systems are disrupted. Information leakage: “not confirmed at this time,” investigation ongoing. Railway operations: no impact at the time of the notice.
Same day, Keio Plaza Hotel published its own notice: ransomware on hotel servers confirmed early Sep 26; external network cut; coordination with Keio Electric Railway, police, and outside experts. Partial system impairment; leak not confirmed; hotel operations continue. Practical friction: official inquiry form and booking-site replies may be delayed or impossible.
Secondary Japanese coverage (ITmedia / group notices through Sep 28): Keio Store (Sep 27) — some stores unable to take credit card / e-money payments or grant/redeem points under the group outage. Keio Presso Inn — new reservations suspended for now. Keio Bus — credit cards unavailable at periodic-pass sales counters. Encrypted-fleet counts, ransom figures, and a named ransomware brand: none appear in the company notices reviewed through Sep 28.
POV: Treat this as a confirmed group ransomware event with retail/hospitality/bus payment and booking pain, and with rail ops explicitly carved out. Leak status and any ransom demand stay Undisclosed / not confirmed until Keio says otherwise. Primaries: Keio Electric Railway + Plaza; the Store / Presso / Bus impact list comes from ITmedia / group notices.
