Japan's leading taxi and chauffeur service, Nihon Kotsu, confirmed a major cyber intrusion that forced the company to suspend critical operations. The breach affects over 8,500 taxis and 2,000 chauffeur vehicles, disrupting booking, dispatch and reservation services.
Key Takeaways
- Malware infection confirmed on Nihon Kotsu's internal network
- Taxi dispatch, web booking, and call center services are offline
- External cybersecurity experts engaged; data leak under investigation
Japan's largest taxi and chauffeur operator Nihon Kotsu issued a statement confirming that its internal systems were compromised by a sophisticated cyberattack over the weekend. The intrusion, detected early Saturday morning, compelled the firm to isolate portions of its IT infrastructure to contain the damage.
Details of the Attack
According to the company's press release, unauthorized external access—identified as a malware infection—penetrated critical servers. Upon detection, emergency protocols were activated, including immediate disconnection of affected systems to prevent further propagation. As a result, services such as car hire, online booking, reservation management, telephone dispatch, and several internal applications remain unavailable.
Business Impact and Customer Guidance
With a workforce of 18,228 and a fleet of 8,558 taxis plus more than 2,000 chauffeur vehicles, Nihon Kotsu generates roughly ¥155 billion (about $1 billion) in annual revenue. The disruption has forced passengers in major metropolitan areas to rely on alternative solutions. The company advises users to switch to the ‘GO’ taxi app or visit nearby taxi stands to secure a ride.
Service Restrictions
In a separate notice, the firm announced the temporary suspension of its “labor taxi” service for pregnant women approaching delivery in Tokyo, Musashino City, Mitaka City, Tachikawa, Yokohama, and Saitama. This restriction adds another layer of inconvenience for a vulnerable customer segment.
Investigation and Data Security
Nihon Kotsu has engaged external cybersecurity specialists to trace the breach, assess system integrity, and restore operations. While no definitive data exfiltration has been confirmed, the company remains vigilant and promises to issue updates through official channels and personalized notices if new information emerges. Customers are cautioned against opening suspicious attachments or clicking links in emails claiming to originate from the firm.
Future Outlook
To date, no ransomware gang or extortion group has claimed responsibility, underscoring the evolving nature of cyber threats against high‑profile transportation providers. The incident highlights the urgent need for continuous investment in advanced threat detection, employee awareness training, and rapid incident response capabilities across the sector.