Three major transport operators in Japan have disclosed serious cyberattacks affecting millions of customers, though railway services continue running normally. Tokyo Metro, Keio Corporation, and Times Car announced separate security incidents between September 25 and 27, according to a report published by Infosecurity Magazine on September 30. The breaches exposed customer data ranging from email addresses to driver's license information, prompting warnings about follow-on phishing attacks.

Tokyo Metro, which transports more than seven million riders daily on some of the capital's busiest subway routes, revealed on September 27 that an unauthorized party accessed email addresses belonging to 59,000 passengers enrolled in its Metpo loyalty program. Keio Corporation, operating a popular line linking central Tokyo to western suburbs, disclosed a ransomware attack on September 26 that disrupted sales systems at certain group companies, including Keio Plaza Hotel. Car-rental firm Times Car announced on September 25 that an intruder penetrated its website the same day, compromising personal details of as many as 6.6 million current and former members. The exposed information includes names, residential and email addresses, birth dates, membership numbers, driver's license details, and identity verification documents.

Tokyo Metro confirmed it identified the suspected entry point for the unauthorized access and implemented measures to block future intrusions, though only email addresses were stolen. The operator urged customers to "exercise particular caution" regarding potential phishing attempts. Keio Corporation stated that police are investigating the attack's scope, "including whether any confidential business information or customer data has been leaked," but noted the company hasn't confirmed any data theft yet and railway operations remain unaffected. Times Car warned that exposed personal information "may be misused in phishing emails and other fraudulent activities," advising customers to watch for suspicious communications impersonating the company and never enter passwords, authentication credentials, or credit card details in unrecognized messages.

The simultaneous timing of the three incidents raises questions about coordination, though no confirmed connection between the Tokyo Metro and Keio breaches has emerged. Both railway operators acted swiftly to contain damage—Tokyo Metro closed the access point, while Keio disconnected systems from the internet to limit the ransomware's spread. Times Car noted that passwords are stored in a format that can't be recovered, eliminating the risk of account misuse through that vector. The Keio Plaza Hotel acknowledged that inquiries submitted through its website contact form and reservation platforms may face longer-than-usual response times, with some queries potentially going unanswered depending on circumstances.

The incidents underscore Japan's transport sector vulnerability at a moment when attackers increasingly target critical infrastructure and high-traffic services. Times Car's breach alone potentially affects 6.6 million individuals, a scale that amplifies phishing risk across the broader population as criminals exploit stolen data for social engineering campaigns. The operators' public warnings about follow-on scams reflect growing recognition that the initial breach is only the opening move—customers now face elevated fraud risk for months ahead, requiring sustained vigilance against messages that leverage authentic personal details to appear legitimate. For businesses managing customer loyalty programs and reservation systems, the trade-off between convenient digital access and hardened security perimeters has never been sharper.