Back to Intelligence

Keio Railway Ransomware Attack: Defending Critical Transportation Infrastructure from Encryption-Based Disruption

SA
Security Arsenal Team
September 29, 2026
11 min read

Keio Corporation, one of Japan's largest private railway operators serving the Tokyo metropolitan area, confirmed its network was struck by an encryption-based cyberattack over the weekend, disrupting portions of its business systems. While Keio's public statements indicate the attack impacted business-side systems rather than train operations directly, this incident is the latest in a sustained pattern of ransomware operators targeting transportation and logistics organizations — a sector where the line between IT disruption and public safety impact is dangerously thin.

This is not an isolated event. Railway and transit operators globally have absorbed repeated ransomware blows over the past several years, and threat actors have learned that transportation organizations carry enormous pressure to restore service quickly — the exact leverage ransomware crews monetize. If you defend any organization with operational continuity requirements — transit, logistics, manufacturing, utilities — this incident is a live case study in why segmentation, backup integrity, and pre-staged incident response matter more than perimeter tools.

Technical Analysis: What We Know and What It Implies

Incident Profile

Based on Keio's disclosure and reporting from BleepingComputer:

  • Attack type: Encryption-based attack — consistent with ransomware or ransomware-style destructive encryption
  • Impact: Disruption to business systems; the company took affected systems offline to contain spread
  • Timing: Weekend execution — a deliberate and well-documented ransomware tradecraft pattern. Operators intentionally detonate encryption on Friday nights and weekends when SOC staffing is thinnest, response times are slowest, and the window before business-hours discovery is longest
  • Attribution: No threat actor had publicly claimed responsibility at the time of reporting, though ransomware groups typically post victims to leak sites within days if negotiations stall

Why Transportation Operators Are High-Value Targets

Railway operators like Keio present a target profile that ransomware affiliates actively hunt:

  1. Flat, legacy networks. Corporate IT often shares trust relationships with scheduling, ticketing, and passenger information systems. Decades-old infrastructure wasn't architected for hostile internal networks.
  2. Availability-driven risk tolerance. Any disruption visible to the public creates immediate reputational and regulatory pressure — leverage for extortion.
  3. Complex vendor ecosystems. Ticketing systems, maintenance platforms, and IoT/OT integrations create third-party ingress paths that are rarely inventoried.
  4. Weekend operational tempo. Transit runs 24/7, but IT/security staffing typically doesn't — and attackers know it.

The Typical Attack Chain We See in These Engagements

While Keio has not released technical indicators, ransomware incidents against comparable transportation and logistics targets in 2025–2026 overwhelmingly follow this pattern, and defenders should hunt against it:

  1. Initial access — compromised VPN/remote access credentials (often infostealer-harvested), phishing-delivered loaders, or exploitation of internet-facing remote access appliances
  2. Persistence and privilege escalation — deployment of Cobalt Strike or similar C2, abuse of legitimate admin tools (PsExec, WMI, WinRM), credential dumping from LSASS
  3. Lateral movement — RDP and SMB spread, often using valid domain admin credentials
  4. Defense evasion — disabling or uninstalling EDR via vssadmin, bcdedit, forced safe-boot, or bring-your-own-vulnerable-driver (BYOVD) techniques
  5. Staging and exfiltration — data staged to RAR/7-Zip archives and exfiltrated to MEGA, Rclone, or attacker-controlled infrastructure before encryption (double extortion)
  6. Detonation — mass encryption pushed via Group Policy, PsExec, or WMI during weekend hours; shadow copies deleted first

The defensive lesson from Keio is not about a single vulnerability — it is about detecting the pre-encryption behaviors that every one of these campaigns shares. Encryption is the last step of a multi-day intrusion. You have days to catch it if you're looking for the right things.

Detection & Response

SIGMA Detections

The following rules target the highest-fidelity pre-encryption behaviors observed in ransomware intrusions against critical infrastructure. These are tuned for low false-positive rates and should be deployed as high-severity alerts.

YAML
---
title: Shadow Copy Deletion via vssadmin or wmic
description: Detects deletion of volume shadow copies, a near-universal precursor to ransomware detonation designed to prevent recovery from local backups.
references:
  - https://attack.mitre.org/techniques/T1490/
author: Security Arsenal
date: 2026/02/15
status: experimental
logsource:
  category: process_creation
  product: windows
detection:
  selection_vssadmin:
    Image|endswith: '\vssadmin.exe'
    CommandLine|contains:
      - 'delete shadows'
      - 'resize shadowstorage'
  selection_wmic:
    Image|endswith: '\wmic.exe'
    CommandLine|contains: 'shadowcopy delete'
  selection_powershell:
    Image|endswith:
      - '\powershell.exe'
      - '\pwsh.exe'
    CommandLine|contains:
      - 'Get-WmiObject Win32_Shadowcopy'
      - 'Get-CimInstance Win32_ShadowCopy'
      - '.Delete()'
  condition: selection_vssadmin or selection_wmic or selection_powershell
falsepositives:
  - Rare legitimate storage reconfiguration by administrators
  - Backup software performing shadow copy management (verify process ancestry)
level: high
tags:
  - attack.impact
  - attack.t1490
id: 8c1a2b3d-4e5f-6a7b-8c9d-0e1f2a3b4c5d
---
title: bcdedit Boot Configuration Tampering for Recovery Suppression
description: Detects modification of boot configuration data to disable recovery mode, a common ransomware technique to prevent safe-mode remediation after encryption.
references:
  - https://attack.mitre.org/techniques/T1490/
author: Security Arsenal
date: 2026/02/15
status: experimental
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    Image|endswith: '\bcdedit.exe'
    CommandLine|contains:
      - 'recoveryenabled no'
      - 'ignoreallfailures'
      - 'bootstatuspolicy'
falsepositives:
  - Hardening scripts in tightly controlled environments (rare)
level: high
tags:
  - attack.impact
  - attack.t1490
id: 9d2b3c4e-5f6a-7b8c-9d0e-1f2a3b4c5d6e
---
title: Mass Encryption Behavior — High-Frequency File Renames with Entropy Indicators
description: Detects suspicious bulk file rename/write patterns consistent with ransomware encryption, keyed on rapid modification of user documents by a single non-backup process.
references:
  - https://attack.mitre.org/techniques/T1486/
author: Security Arsenal
date: 2026/02/15
status: experimental
logsource:
  category: file_event
  product: windows
detection:
  selection:
    TargetFilename|endswith:
      - '.docx'
      - '.xlsx'
      - '.pdf'
      - '.pptx'
      - '.zip'
      - '.bak'
      - '.mdf'
      - '.ldf'
      - '.vmdk'
  filter_legit:
    Image|endswith:
      - '\explorer.exe'
      - '\winword.exe'
      - '\excel.exe'
  condition: selection and not filter_legit
falsepositives:
  - Enterprise search indexers and DLP agents (baseline per host)
  - Legitimate backup/archiving processes — tune by Image path
level: medium
tags:
  - attack.impact
  - attack.t1486
id: 1e3c4d5f-6a7b-8c9d-0e1f-2a3b4c5d6e7f

KQL Hunt Query (Microsoft Sentinel / Defender)

This query hunts the pre-detonation chain — shadow copy deletion, recovery suppression, and suspicious admin-tool lateral movement — correlating across a host within a short window. A single host exhibiting two or more of these behaviors in 30 minutes is a near-certain incident.

KQL — Microsoft Sentinel / Defender
let Lookback = 7d;
let RansomwarePreDetonation =
    DeviceProcessEvents
    | where TimeGenerated > ago(Lookback)
    | where (FileName =~ "vssadmin.exe" and ProcessCommandLine has_any ("delete shadows", "resize shadowstorage"))
        or (FileName =~ "bcdedit.exe" and ProcessCommandLine has_any ("recoveryenabled", "bootstatuspolicy", "ignoreallfailures"))
        or (FileName =~ "wmic.exe" and ProcessCommandLine has "shadowcopy delete")
        or (FileName in~ ("powershell.exe", "pwsh.exe") and ProcessCommandLine has "Win32_ShadowCopy")
    | project TimeGenerated, DeviceName, FileName, ProcessCommandLine, InitiatingProcessFileName, InitiatingProcessCommandLine, AccountName;
let SuspiciousAdminToolSpread =
    DeviceProcessEvents
    | where TimeGenerated > ago(Lookback)
    | where FileName in~ ("psexec.exe", "psexesvc.exe", "wmic.exe")
        or (FileName =~ "cmd.exe" and ProcessCommandLine has_any ("\\admin$", "\\c$"))
    | project TimeGenerated, DeviceName, FileName, ProcessCommandLine, InitiatingProcessFileName, AccountName;
union RansomwarePreDetonation, SuspiciousAdminToolSpread
| summarize Behaviors = dcount(FileName), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated), Commands = make_set(ProcessCommandLine, 10) by DeviceName, AccountName
| where Behaviors >= 2 or (Behaviors >= 1 and Commands has_any ("delete shadows", "shadowcopy delete", "recoveryenabled no"))
| sort by Behaviors desc, FirstSeen asc;

For Linux-heavy environments ingesting Syslog/CEF into Sentinel (common for transit operators running mixed estates), hunt for mass file operations and suspicious archive staging:

KQL — Microsoft Sentinel / Defender
Syslog
| where TimeGenerated > ago(7d)
| where ProcessName in~ ("tar", "7z", "rar", "zip", "openssl", "rclone")
    or SyslogMessage has_any ("ransom", "encrypted", "decrypt your files")
| summarize count() by Computer, ProcessName, bin(TimeGenerated, 10m)
| where count_ > 50
| sort by count_ desc;

Velociraptor VQL Hunt

Use this hunt across the fleet to identify hosts showing active encryption precursors — processes touching shadow copies, suspicious child processes of Office or browsers (initial-access loaders), and recently written ransom-note-style artifacts:

VQL — Velociraptor
-- Ransomware pre-detonation and ransom-note artifact hunt
LET proc_hits = SELECT Pid, Name, CommandLine, Exe, Username, CreateTime,
       ppid() AS ParentPid
FROM pslist()
WHERE CommandLine =~ '(?i)(delete shadows|shadowcopy delete|recoveryenabled no|ignoreallfailures|resize shadowstorage)'
   OR Name =~ '(?i)(psexec|psexesvc)'

LET ransom_notes = SELECT FullPath, Size, Mtime, Ctime
FROM glob(globs=['C:/Users/*/Desktop/*decrypt*', 'C:/Users/*/Desktop/*recover*',
                 'C:/Users/*/Documents/*readme*decrypt*', 'C:/ProgramData/*how_to*',
                 'C:/Users/*/Desktop/*ransom*'],
          accessor='file')
WHERE Mtime > now() - 604800

SELECT * FROM proc_hits
UNION ALL
SELECT NULL AS Pid, 'RANSOM_NOTE_ARTIFACT' AS Name, FullPath AS CommandLine,
       NULL AS Exe, NULL AS Username, Mtime AS CreateTime, NULL AS ParentPid
FROM ransom_notes

Hardening and Verification Script

The following PowerShell script verifies the defensive posture most relevant to this attack class — shadow copy protection status, SMB hardening, EDR presence, and backup service health. Run it across your fleet weekly and alert on deviations. Do not wait for an incident to discover your backups were silently failing.

PowerShell
# Ransomware resilience verification — run as SYSTEM/admin on domain-joined hosts
# Output is designed for ingestion into a CMDB or SIEM via scheduled task

$results = [ordered]@{ Hostname = $env:COMPUTERNAME; Timestamp = (Get-Date).ToString('o') }

# 1. Verify VSS service is not disabled
$vss = Get-Service -Name VSS -ErrorAction SilentlyContinue
$results['VSS_StartType'] = $vss.StartType
$results['VSS_Disabled'] = ($vss.StartType -eq 'Disabled')

# 2. Check existing shadow copies exist (recovery capability present)
$shadows = Get-CimInstance Win32_ShadowCopy -ErrorAction SilentlyContinue
$results['ShadowCopiesPresent'] = ($null -ne $shadows -and $shadows.Count -gt 0)

# 3. Verify SMBv1 is disabled (wormable legacy protocol)
$smb1 = Get-SmbServerConfiguration | Select-Object -ExpandProperty EnableSMB1Protocol
$results['SMBv1_Disabled'] = (-not $smb1)

# 4. Confirm tamper protection / EDR service running (Defender as baseline)
$mp = Get-Service -Name WinDefend -ErrorAction SilentlyContinue
$results['DefenderRunning'] = ($mp.Status -eq 'Running')
$tamper = (Get-MpComputerStatus -ErrorAction SilentlyContinue).IsTamperProtected
$results['TamperProtection'] = $tamper

# 5. Verify backup agent/service health (adjust service names for your backup platform)
$backupServices = @('VeeamDeploySvc','VeeamBackupSvc','wbengine') | ForEach-Object {
    Get-Service -Name $_ -ErrorAction SilentlyContinue
}
$results['BackupServiceFound'] = ($null -ne ($backupServices | Where-Object { $_.Status -eq 'Running' }))

# 6. Check LSASS protection (credential dump mitigation)
$lsa = Get-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Control\Lsa' -Name RunAsPPL -ErrorAction SilentlyContinue
$results['LSA_PPL_Enabled'] = ($lsa.RunAsPPL -eq 1)

# 7. Lateral movement surface: is WinRM exposed unnecessarily?
$winrm = Get-Service -Name WinRM -ErrorAction SilentlyContinue
$results['WinRM_Running'] = ($winrm.Status -eq 'Running')

# Emit and flag failures
[PSCustomObject]$results
$failures = $results.GetEnumerator() | Where-Object {
    $_.Key -in @('VSS_Disabled','ShadowCopiesPresent','SMBv1_Disabled','DefenderRunning','TamperProtection','BackupServiceFound','LSA_PPL_Enabled') -and
    ($_.Value -eq $false -and $_.Key -ne 'VSS_Disabled' -or ($_.Key -eq 'VSS_Disabled' -and $_.Value -eq $true))
}
if ($failures) { Write-Warning "RANSOMWARE RESILIENCE GAPS: $(($failures.Key) -join ', ')"; exit 1 } else { Write-Host 'All resilience checks passed.'; exit 0 }

Remediation and Hardening Recommendations

If you are responding to an active encryption event, your first 60 minutes determine whether this is a contained incident or an enterprise-wide outage:

Immediate containment (first hour):

  1. Isolate, don't power off. Network-isolate affected hosts and VLANs at the switch level. Pulling power destroys volatile forensic evidence (memory-resident malware, encryption keys in RAM) and can corrupt partially encrypted databases.
  2. Disable compromised identity infrastructure. Force-reset domain admin, service account, and any credentials that touched affected hosts. Assume Kerberos tickets are compromised — consider a full krbtgt double-reset in confirmed enterprise intrusions.
  3. Block C2 and exfil channels at the perimeter. Egress-filter known ransomware staging destinations (MEGA, Rclone endpoints, anonymous file-sharing services) and newly registered domains observed in DNS logs.
  4. Preserve evidence before remediation. Capture memory and triage images from patient-zero hosts before rebuilding. You will need this for attribution, insurance claims, and regulatory notification — Keio's disclosure obligations under Japan's APPI and sector regulators apply to many of your organizations under equivalent regimes (NERC CIP, TSA security directives for rail, GDPR, state breach laws).

Structural hardening (the work that prevents the next Keio):

  1. Segment business IT from operational systems. Ticketing, scheduling, and passenger-facing systems must not share domain trust or flat network paths with corporate workstations. Enforce deny-by-default firewall rules between segments and broker all administrative access through hardened jump hosts with MFA.
  2. Immutable, offline, tested backups. Maintain at least one backup copy that is logically or physically air-gapped (immutable object storage, WORM, or offline media) with a service account that cannot be used interactively. Test restoration quarterly — a backup you've never restored is a hypothesis, not a control.
  3. Deploy the detections above and alert aggressively on pre-encryption behaviors. Shadow copy deletion on any endpoint is a page-the-on-call event, not an informational alert.
  4. Weekend and holiday coverage. Ransomware detonates when you're understaffed. If you cannot staff 24/7 internally, contract an MDR provider with authority to isolate hosts autonomously during off-hours. Pre-authorize containment actions in writing — the worst time to negotiate isolation authority is 2 a.m. Sunday during an active detonation.
  5. MFA on all remote access, without exception. The dominant initial-access vector in 2025–2026 ransomware engagements remains valid credentials against VPN and remote access gateways. Phishing-resistant MFA (FIDO2) and conditional access policies close this door.
  6. Third-party and vendor access inventory. Map every vendor with remote access to your environment, enforce named accounts (no shared vendor credentials), and log all sessions. Transit operators' maintenance and ticketing vendors are a proven ingress path.
  7. Exercise your IR plan against this exact scenario. Tabletop a "ransomware detonates Saturday at 1 a.m., domain admin compromised, backups partially encrypted" scenario. Include communications, legal counsel, cyber insurance notification timelines, and executive decision-makers. Keio's incident is your free tabletop inject.

Regulatory note: Operators of critical transportation infrastructure should review applicable government reporting requirements — in Japan, relevant ministries and JPCERT/CC; in the US, TSA Security Directives for passenger and freight rail require cybersecurity incident reporting to CISA within prescribed windows; CIRCIA reporting obligations apply to covered critical infrastructure entities. Know your deadlines before an incident, not during one.

Related Resources

Security Arsenal Incident Response Services AlertMonitor Platform Book a SOC Assessment incident-response Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.