Visualização de leitura

Malware Hits Japan’s Largest Taxi Company Nihon Kotsu, Services Temporarily Suspended

Japan’s largest taxi operator Nihon Kotsu shut down systems after a malware attack, disrupting dispatch and bookings.

Nihon Kotsu, Japan’s largest taxi company, disclosed on July 13, 2026 that its internal systems suffered an unauthorized external access involving malware infection in the early morning hours of Saturday, July 11. The company immediately shut down systems as an emergency measure to contain the damage. As a result, its online car hire reservation system, telephone-based taxi dispatch service, and several internal systems are currently unavailable.

The company’s public notice was direct about the sequence of events.

“We have recently discovered that our internal systems were subjected to unauthorized external access (malware infection). We sincerely apologize for the great inconvenience and concern this has caused to our customers, business partners, and all other parties involved.” reads the company’s notice. “Upon detecting the unauthorized access, we immediately took emergency measures, including shutting down systems, to prevent further damage. As a result, our hire car web order and reservation management system, telephone-based taxi dispatch service, and some internal systems are currently temporarily unavailable.”

The company took systems offline to contain the threat, but it caused operational disruption.

With the telephone dispatch service down, customers who need a Nihon Kotsu taxi are being directed to use the GO taxi app and select Nihon Kotsu as the company when requesting a ride, or to find a nearby taxi stand or flag one down on the street. It’s a significant operational gap for a company that runs one of Tokyo’s most recognizable fleets, but the manual workaround is functional. The hire car reservation system, which handles advance bookings, remains offline.

Nihon Kotsu confirmed it’s working with external security experts to determine the scope of the securty incident, identify the cause, and analyze logs. The internal network has been isolated to prevent further spread. On the question of personal data exposure, the company said: “We are currently conducting a detailed investigation with specialized agencies into whether and to what extent data has been leaked. At this time, no information leak has been confirmed. However, in the unlikely event that we discover any leak or potential leak of personal information of our customers or related parties, we will promptly make an official announcement and contact those affected individually, in accordance with the law.”

That’s a carefully worded statement: confirmed is doing real work there, and the investigation is still open.

Nihon Kotsu said no data leak has been confirmed. If the investigation finds customer data was exposed, it will notify affected individuals and publicly disclose the incident as required by Japan’s Act on the Protection of Personal Information.

The Japanese firm is prioritizing secure system recovery and will provide updates as the investigation progresses. The company also warned customers to ignore suspicious emails or messages impersonating the firm.

“We are prioritizing the security of our system and the recovery process in a safe environment. We will publish updates on the investigation and recovery status on this website as soon as they become available.” concludes the notice. “Please be careful not to open any attachments or click on any links if you receive any suspicious emails or communications impersonating our company.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

Nihon Kotsu Cyberattack Disrupts Japan’s Largest Taxi Operator

Nihon Kotsu cyberattack

The Nihon Kotsu cyberattack has disrupted operations at Japan's largest taxi operator after the company confirmed that its internal systems were compromised by a malware-related security incident. The cyberattack on Nihon Kotsu forced the company to shut down parts of its IT infrastructure, leaving key Japan taxi service operations, including its taxi dispatch system, unavailable.  According to the company, the incident occurred early on Saturday, July 11, 2026. After detecting unauthorized access, Nihon Kotsu immediately shut down affected systems to contain the attack and prevent additional damage. The taxi dispatch service operated via telephone, the hire car web ordering and reservation management system, and several internal systems remain temporarily offline. 

Nihon Kotsu Shuts Down Systems 

Nihon Kotsu, Japan's largest taxi and chauffeur operator by group revenue, generates approximately ¥155 billion (around $1 billion) annually. The company employs 18,228 people and operates a fleet of 8,558 taxis alongside more than 2,000 chauffeur vehicles, making the disruption significant for the country's Japan taxi service sector.  In a statement, the company said, "We have confirmed that our internal systems were subjected to unauthorized external access (malware infection)." It also apologized for the incident, stating, "We sincerely apologize for the great inconvenience and concern this has caused to our customers, business partners, and all other parties involved." 

Japan Taxi Service Affected as Dispatch Operations Remain Offline 

The company explained that emergency measures were implemented immediately after the breach was detected. "Upon detecting the unauthorized access, we immediately took emergency measures, including shutting down systems, to prevent further damage," the statement said. It added that the disruption has affected web-based hire car reservations, telephone taxi dispatch services, and certain internal systems.  As the cyberattack on Nihon Kotsu continues to be investigated, customers requiring taxis have been advised to use the GO taxi application, nearby taxi stands, or hail a cab directly from the street. Users of the GO app can still request a Nihon Kotsu vehicle by selecting the company within the application.  The company said it is working with external cybersecurity specialists to determine the cause of the incident, analyze system logs, and assess the overall impact. According to the statement, the internal network has been isolated, and "further spread of the damage has been contained." 

Investigation into the Nihon Kotsu Cyberattack Continues 

Investigators are also examining whether any personal or corporate data was exposed during the Nihon Kotsu cyberattack. The company stated that no information leak has been confirmed at this stage.   However, it noted that a detailed investigation is ongoing with specialized agencies to determine whether any data was compromised. If customer or partner information is found to have been exposed, Nihon Kotsu said it will make a public announcement and individually notify affected parties in accordance with applicable laws.  The company said restoring systems securely remains its highest priority. It also pledged to provide updates on both the investigation and recovery process as more information becomes available. In the meantime, Nihon Kotsu urged customers to remain cautious of fraudulent emails or messages claiming to originate from the company and advised them not to open suspicious attachments or click unknown links. 
❌