Back to Intelligence

Keio Corporation & Tokyo Metro Breaches: Ransomware Detection and Hardening Guide for Transportation Operators

SA
Security Arsenal Team
October 1, 2026
12 min read

Two of Japan's largest railway operators — Keio Corporation and Tokyo Metro — disclosed security breaches in the same reporting window, and the timing should put every transportation and critical infrastructure security team on alert. Keio, one of Japan's major private railway operators, was hit by an encryption-based cyber incident over the weekend. The company detected a system failure early Saturday, confirmed disruption to business systems, and made the decision to shut down its entire network to contain the spread. Tokyo Metro separately disclosed its own security breach.

While the operators have not yet confirmed ransomware attribution publicly, the observable pattern — weekend timing, encryption of business systems, and an emergency full-network shutdown — matches the standard playbook of modern ransomware intrusions we've responded to dozens of times. Attackers deliberately time detonation for weekends and holidays when SOC staffing is thinnest and MTTD (mean time to detect) stretches from minutes to hours.

This post breaks down what defenders should take from these incidents: how encryption-based attacks present in enterprise telemetry, what to hunt for before detonation, and the concrete hardening steps that separate a contained incident from a company-wide network shutdown.

Technical Analysis

What We Know

  • Victim: Keio Corporation — a major Japanese private railway operator serving the Tokyo metropolitan area, with business operations spanning rail, bus, retail, and real estate.
  • Attack type: Encryption-based cyber incident (ransomware-pattern behavior) impacting business systems.
  • Detection point: A system failure detected early Saturday morning — consistent with mass encryption detonating outside business hours.
  • Containment action: Full network shutdown. This is the correct containment call for uncontrolled encryption spread, but it carries enormous operational cost for a transportation operator.
  • Second victim: Tokyo Metro disclosed a separate security breach in the same period. Whether the two incidents are linked (shared supplier, common access broker, or opportunistic campaign) has not been established — but simultaneous disclosures from organizations in the same sector and geography warrant treating this as a potential sector-targeted campaign, not isolated bad luck.

The Attack Chain (Defender's View)

No CVE has been disclosed in connection with these incidents, and defenders should not wait for one. In the majority of ransomware engagements we've led, initial access comes from a small set of repeatable vectors rather than novel zero-days:

  1. Initial access — Compromised VPN/remote access credentials (often purchased from access brokers), phishing with credential harvesting, or exploitation of an internet-facing appliance. The 2025–2026 wave of edge-device exploitation (VPN concentrators, firewalls, remote access gateways) remains the dominant entry point in our caseload.
  2. Persistence and privilege escalation — Valid account abuse, creation of rogue local/domain admin accounts, and scheduled tasks or services for survivability.
  3. Discovery and lateral movement — net.exe enumeration, BloodHound/SharpHound collection, RDP and SMB (admin$) pivoting, and deployment via PsExec, GPO, or SCCM-style software distribution abuse.
  4. Impact preparation — The highest-fidelity pre-detonation signals: shadow copy deletion (vssadmin delete shadows, wmic shadowcopy delete, bcdedit recovery tampering), backup server access, and mass disabling of security tools.
  5. Detonation — Mass file encryption with high-entropy file writes, uniform extension renames, ransom note drops (README, DECRYPT, HOW_TO_RESTORE patterns), and wallpaper changes.

The critical defensive insight: stages 1–4 are detectable for hours to days before stage 5. Keio's Saturday-morning detection at the "system failure" stage means the pre-detonation telemetry almost certainly existed — the question is whether anyone was positioned to see it.

Why Transportation Operators Are Prime Targets

  • Operational pressure to pay: Any downtime cascades into public safety, scheduling, and revenue impact — attackers know a railway can't stay dark for weeks.
  • IT/OT adjacency: Business systems and operational technology often share identity infrastructure (a single AD forest), making containment without operational disruption extremely difficult.
  • Large, distributed attack surface: Stations, depots, ticketing systems, and contractor remote access multiply entry points.
  • Weekend/holiday detonation windows: Attackers time encryption for minimum staffing — exactly what happened here.

Detection & Response

The detections below target the highest-signal, lowest-noise behaviors in the ransomware kill chain. Every rule was selected because it fires on a behavior with essentially no legitimate business justification — the kind of alert a SOC can page on at 2 a.m. with confidence.

Sigma Rules

YAML
---
title: Shadow Copy Deletion via vssadmin wmic or bcdedit
id: 9c4e2a71-3b58-4f6d-9e21-7a2b5c8d1f34
status: experimental
description: Detects deletion of volume shadow copies or tampering with boot recovery options, a hallmark pre-encryption ransomware behavior observed in incidents like the Keio Corporation encryption attack.
references:
  - https://attack.mitre.org/techniques/T1490/
  - https://securityaffairs.com/200027/data-breach/japanese-railway-operators-keio-corporation-and-tokyo-metro-disclose-security-breaches.html
author: Security Arsenal
date: 2026/04/06
tags:
  - attack.impact
  - attack.t1490
logsource:
  category: process_creation
  product: windows
detection:
  selection_vssadmin:
    Image|endswith: '\vssadmin.exe'
    CommandLine|contains:
      - 'delete shadows'
      - 'resize shadowstorage'
  selection_wmic:
    Image|endswith: '\wmic.exe'
    CommandLine|contains: 'shadowcopy'
  selection_bcdedit:
    Image|endswith: '\bcdedit.exe'
    CommandLine|contains:
      - 'recoveryenabled no'
      - 'ignoreallfailures'
  selection_powershell:
    Image|endswith:
      - '\powershell.exe'
      - '\pwsh.exe'
    CommandLine|contains:
      - 'Get-WmiObject Win32_Shadowcopy'
      - 'Remove-CimInstance'
      - 'Win32_ShadowCopy |'
  condition: 1 of selection_*
falsepositives:
  - Rare backup or storage administration scripts; validate against change windows
level: critical
---
title: Mass File Rename with Uniform Extension (Ransomware Encryption Behavior)
id: 2f7d9b13-6e41-4a5c-8d92-1e3f6a7b9c05
status: experimental
description: Detects a single process renaming or writing a high volume of files with a uniform new extension in a short window, indicating active mass encryption as seen in the Keio incident.
references:
  - https://attack.mitre.org/techniques/T1486/
  - https://securityaffairs.com/200027/data-breach/japanese-railway-operators-keio-corporation-and-tokyo-metro-disclose-security-breaches.html
author: Security Arsenal
date: 2026/04/06
tags:
  - attack.impact
  - attack.t1486
logsource:
  category: file_rename
  product: windows
detection:
  selection:
    Image|endswith:
      - '\rundll32.exe'
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\cmd.exe'
      - '\wscript.exe'
      - '\cscript.exe'
  filter_known_encryptors:
    TargetFilename|endswith:
      - '.tmp'
      - '.log'
  condition: selection and not filter_known_encryptors
falsepositives:
  - Bulk file conversion utilities; tune per environment baselines
level: high
---
title: Ransom Note Artifact Creation
id: 5b1c8e42-7d63-4f2a-b981-4c6d2e9a0f17
status: experimental
description: Detects creation of common ransom note filenames across user-writable directories, an immediate indicator that encryption detonation has occurred or is in progress.
references:
  - https://attack.mitre.org/techniques/T1486/
  - https://securityaffairs.com/200027/data-breach/japanese-railway-operators-keio-corporation-and-tokyo-metro-disclose-security-breaches.html
author: Security Arsenal
date: 2026/04/06
tags:
  - attack.impact
  - attack.t1486
logsource:
  category: file_event
  product: windows
detection:
  selection:
    TargetFilename|contains:
      - 'README_FOR_DECRYPT'
      - 'HOW_TO_DECRYPT'
      - 'DECRYPT_INSTRUCTION'
      - 'HOW_TO_RESTORE'
      - 'RECOVER_FILES'
      - 'RESTORE_FILES_INFO'
      - '!README!'
      - 'READ_ME_TO_RECOVER'
falsepositives:
  - Security awareness simulations and red team exercises
level: critical

KQL Hunt Query (Microsoft Sentinel / Defender)

This query hunts the pre-detonation phase — the hours where Keio's defenders could have acted before the Saturday-morning failure. It correlates shadow copy tampering with the spawning process tree so analysts can pivot directly to the source host and user.

KQL — Microsoft Sentinel / Defender
// Hunt ransomware pre-detonation behavior: shadow copy deletion + recovery tampering
// and correlate with parent process for rapid scoping.
let TamperCommands = dynamic(["vssadmin", "wmic", "bcdedit", "diskshadow"]);
let TamperPatterns = dynamic(["delete shadows", "shadowcopy delete", "recoveryenabled no",
    "ignoreallfailures", "shadowstorage", "Win32_Shadowcopy"]);
union isfuzzy=true
    (DeviceProcessEvents
    | where TimeGenerated > ago(14d)
    | where FileName in~ (TamperCommands)
    | where ProcessCommandLine has_any (TamperPatterns)
    | project TimeGenerated, DeviceName, AccountName, FileName, ProcessCommandLine,
              InitiatingProcessFileName, InitiatingProcessCommandLine, ProcessId, SHA256),
    (SecurityEvent
    | where TimeGenerated > ago(14d)
    | where EventID == 4688
    | where Process has_any (TamperCommands)
    | where CommandLine has_any (TamperPatterns)
    | project TimeGenerated, DeviceName = Computer, AccountName = Account,
              FileName = Process, ProcessCommandLine = CommandLine,
              InitiatingProcessFileName = ParentProcessName,
              InitiatingProcessCommandLine = "", ProcessId = NewProcessId, SHA256 = "")
)
| extend HourBucket = bin(TimeGenerated, 1h)
| summarize EventCount = count(), Hosts = dcount(DeviceName),
            FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated)
  by DeviceName, AccountName, FileName, ProcessCommandLine, InitiatingProcessFileName
| order by FirstSeen asc;
// PIVOT: any hit here is page-worthy. Immediately check the same host for:
// DeviceFileEvents | where DeviceName == "<host>" | where FolderPath has_any ("README","DECRYPT","RESTORE")
// and count file rename velocity:
// DeviceFileEvents | where DeviceName == "<host>" and ActionType == "FileRenamed"
// | summarize renames=count() by bin(TimeGenerated, 1m) | where renames > 50

Velociraptor VQL Hunt

Use this artifact for fleet-wide sweeping of suspected hosts — it pulls processes exhibiting tamper commands, checks for ransom note artifacts on disk, and enumerates recently executed binaries from user-writable paths (a common ransomware staging location).

VQL — Velociraptor
-- Ransomware pre/post-detonation sweep: tamper processes, ransom notes, staged binaries
SELECT * FROM foreach(
  row={
    SELECT Pid, Name, CommandLine, Exe, Username, CreateTime
    FROM pslist()
    WHERE CommandLine =~ '(?i)(vssadmin.*delete|shadowcopy|bcdedit.*recoveryenabled|diskshadow)'
       OR Exe =~ '(?i)(\\\\(temp|tmp|appdata|programdata)\\\\[^\\\\]+\.exe$)'
  },
  query={
    SELECT Pid, Name, CommandLine, Exe, Username, CreateTime,
           'process_indicator' AS IndicatorType
    FROM scope()
  }
)
UNION ALL
SELECT NULL AS Pid, 'RANSOM_NOTE' AS Name, FullPath AS CommandLine,
       '' AS Exe, '' AS Username, Mtime AS CreateTime,
       'ransom_note_artifact' AS IndicatorType
FROM glob(globs=[
    'C:/Users/*/Desktop/*DECRYPT*',
    'C:/Users/*/Desktop/*README*RESTORE*',
    'C:/Users/*/Documents/*HOW_TO_DECRYPT*',
    'C:/**/RECOVER_FILES*',
    'C:/**/RESTORE_FILES_INFO*'
], root='/')
WHERE Mtime > now() - 1209600  -- artifacts from the last 14 days

Remediation & Hardening Script

Run this PowerShell verification script (elevated, fleet-wide via your RMM or GPO startup script) to confirm the defenses that would have blunted this attack are actually in place. It checks shadow copy protection, controlled folder access, LAPS deployment, and SMBv1 — the controls that most frequently turn out to be misconfigured during our post-incident reviews.

PowerShell
# ============================================================
# Ransomware Resilience Verification — Keio/Tokyo Metro Lessons
# Run elevated. Outputs PASS/FAIL per control for fleet reporting.
# ============================================================

$results = @()

# 1. Verify VSS is enabled and shadow copies exist on system drive
try {
    $shadows = Get-CimInstance Win32_ShadowCopy -ErrorAction Stop
    $vss = Get-Service VSS -ErrorAction Stop
    $status = if ($shadows -and $vss.Status -eq 'Running') { 'PASS' } else { 'FAIL' }
    $results += [PSCustomObject]@{ Control='VSS Enabled + Copies Exist'; Status=$status; Detail="Copies: $($shadows.Count); VSS: $($vss.Status)" }
} catch { $results += [PSCustomObject]@{ Control='VSS Enabled + Copies Exist'; Status='FAIL'; Detail=$_.Exception.Message } }

# 2. Microsoft Defender Controlled Folder Access (blocks unauthorized mass encryption)
$cfa = (Get-MpPreference).EnableControlledFolderAccess
$cfaState = switch ($cfa) { 1 {'PASS (Enabled)'} 2 {'PASS (Audit)'} default {'FAIL (Disabled)'} }
$results += [PSCustomObject]@{ Control='Controlled Folder Access'; Status=$cfaState; Detail="Value: $cfa" }

# 3. Defender real-time protection + tamper protection
$mp = Get-MpComputerStatus
$results += [PSCustomObject]@{ Control='Defender Real-Time Protection'; Status=($(if($mp.RealTimeProtectionEnabled){'PASS'}else{'FAIL'})); Detail="RTP: $($mp.RealTimeProtectionEnabled)" }
$results += [PSCustomObject]@{ Control='Tamper Protection'; Status=($(if($mp.IsTamperProtected){'PASS'}else{'FAIL'})); Detail="TamperProtected: $($mp.IsTamperProtected)" }

# 4. Attack Surface Reduction: block credential theft from LSASS (ASR rule 9e6c4e1f-7d60-472f-ba1a-a39ef669e4b2)
$asr = (Get-MpPreference).AttackSurfaceReductionRules_Ids
$asrActions = (Get-MpPreference).AttackSurfaceReductionRules_Actions
$idx = [array]::IndexOf($asr, '9e6c4e1f-7d60-472f-ba1a-a39ef669e4b2')
$asrStatus = if ($idx -ge 0 -and $asrActions[$idx] -eq 1) { 'PASS' } else { 'FAIL' }
$results += [PSCustomObject]@{ Control='ASR: Block LSASS Credential Theft'; Status=$asrStatus; Detail='Rule 9e6c4e1f-7d60-472f-ba1a-a39ef669e4b2' }

# 5. SMBv1 disabled (legacy lateral movement vector)
$smb1 = Get-WindowsOptionalFeature -Online -FeatureName SMB1Protocol -ErrorAction SilentlyContinue
$results += [PSCustomObject]@{ Control='SMBv1 Disabled'; Status=($(if($smb1.State -eq 'Disabled'){'PASS'}else{'FAIL'})); Detail="State: $($smb1.State)" }

# 6. LAPS deployed (breaks pass-the-hash lateral movement with shared local admin creds)
$laps = Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\LAPS' -ErrorAction SilentlyContinue
$legacyLaps = Get-CimInstance -Namespace root\cimv2 -ClassName Win32_Product -ErrorAction SilentlyContinue | Where-Object { $_.Name -like '*LAPS*' }
$results += [PSCustomObject]@{ Control='Windows LAPS Configured'; Status=($(if($laps -or $legacyLaps){'PASS'}else{'FAIL'})); Detail='Checks HKLM LAPS policy key' }

# 7. RDP exposure check — should not be listening on 0.0.0.0 with NLA disabled
$nla = (Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name UserAuthentication -ErrorAction SilentlyContinue).UserAuthentication
$results += [PSCustomObject]@{ Control='RDP Network Level Authentication'; Status=($(if($nla -eq 1){'PASS'}else{'FAIL'})); Detail="NLA: $nla" }

$results | Format-Table -AutoSize
$results | Export-Csv -Path "$env:TEMP\ransomware_resilience_$(hostname)_$(Get-Date -Format yyyyMMdd).csv" -NoTypeInformation

# HARDENING (uncomment to enforce rather than audit):
# Set-MpPreference -EnableControlledFolderAccess Enabled
# Add-MpPreference -AttackSurfaceReductionRules_Ids 9e6c4e1f-7d60-472f-ba1a-a39ef669e4b2 -AttackSurfaceReductionRules_Actions Enabled
# vssadmin Create Shadow /For=C:

Remediation

These incidents have no published CVE and no vendor patch — remediation here is architectural, not a version number. Prioritize in this order:

Immediate (24–72 hours):

  1. Hunt your environment with the queries above. If shadow copy tampering or ransom note artifacts appear anywhere, treat it as an active incident and isolate the host from the network immediately.
  2. Audit remote access. Enumerate every VPN, RDP, and third-party remote support path into your network. Enforce phishing-resistant MFA (FIDO2 where possible) on all of them. Invalidate sessions and rotate credentials for any account with remote access that lacks MFA.
  3. Verify backup integrity and isolation. Confirm backups are offline or immutable (object lock / air-gapped), that backup infrastructure uses separate credentials from the production domain, and — critically — perform a test restore. In our ransomware engagements, "we had backups" and "we could restore from backups" have proven to be very different statements.
  4. Enable Controlled Folder Access and ASR rules in audit mode at minimum, block mode on servers and high-value endpoints.

Short-term (1–4 weeks): 5. Deploy Windows LAPS to eliminate shared local administrator credentials — the single most effective lateral movement brake in a Windows environment. 6. Segment identity from operations. For transportation and industrial operators: business IT and OT must not share a single AD trust path. Keio's full-network shutdown is what happens when segmentation fails — the only safe containment option is to pull everything. 7. Weekend/holiday alerting posture. Attackers detonate on weekends because they work. Ensure your SOC (in-house or MDR) pages a human for shadow-copy-deletion and mass-rename alerts regardless of the day or hour — these are two of the highest-fidelity signals in all of endpoint telemetry.

Structural (quarter): 8. Tabletop the "full network shutdown" scenario. Keio's response was correct but costly. Run an exercise answering: who has authority to order a network-wide shutdown, how do you communicate when email is down, and how do you safely reintroduce segments without reinfection? 9. Third-party and sector intelligence sharing. With two major Tokyo rail operators disclosing breaches simultaneously, assume shared exposure — common suppliers, MSPs, or access brokers. Join your sector's ISAC (transportation operators: relevant ISACs and JPCERT/CC for Japan-facing organizations) and act on shared indicators quickly. 10. Review CISA's #StopRansomware guidance and cross-map your controls against the joint advisories at cisa.gov/stopransomware — the pre-detonation TTPs documented there match this incident's profile almost exactly.

Related Resources

Security Arsenal Incident Response Services AlertMonitor Platform Book a SOC Assessment incident-response Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.