Dormant High impact Ransomware Checked 3d ago

Ransomware hits Japan's largest taxi operator Nihon Kotsu

Nihon Kotsu, Japan's biggest taxi and limousine operator, found unauthorized access to its internal systems on July 11, 2026 and shut down affected IT infrastructure, taking its taxi dispatch system offline. On July 15 the ransomware group AiLock claimed the attack and threatened to leak stolen data if the company does not pay. On July 22 Nihon Kotsu said it had found information suspected of being leaked but was still investigating. On August 19 the company issued a fourth notice confirming that some of the files it held had in fact leaked outside the company, while saying the investigation into the full scope was continuing. A Japanese tech outlet had reported in mid August that a file list posted by the attackers, still not fully published at that point, reportedly includes internal driver conduct records.

Started
Jul 11, 2026
Latest activity
Aug 19, 2026
Attributed to
AiLockSuspected
Where
Japan
Sectors
Transport
Scale
one company, Japan's largest taxi and chauffeur operator with over 8,500 taxis and 2,000 chauffeur vehicles

Current status

No fifth notice or new development found; Nihon Kotsu's official news feed through September 8, 2026 shows no update after the August 19 fourth notice, and a ScanNetSecurity piece dated September 4-6, 2026 only restates that same fourth notice.

Dormant: No new confirmed activity for a while, and nobody has called an official all clear.

Who is behind it

Attribution is still based only on AiLock's own claim; no government agency or the company has named the attacker.

Impact

The company's taxi dispatch and reservation systems went down, disrupting bookings for one of Japan's biggest taxi fleets. Nihon Kotsu has now confirmed that some of the files it held did leak outside the company, though it has not detailed exactly what was in those files or how many people are affected. A file list the attackers posted earlier, according to Japanese press reports, appears to include drivers' internal disciplinary records covering things like drunk driving and hit-and-run incidents, and possibly a backup of a company database and stored dashcam passwords. The company says it is working with outside security specialists on recovery and will notify affected individuals once its investigation confirms what leaked.

What to do

Nihon Kotsu customers and drivers should watch for official company notices about whether their own personal data was among the leaked files, and be wary of any unexpected messages claiming to be from the company until it confirms what was taken.

Timeline

  1. Sep 9, 2026

    No new confirmed activity reported, so this incident moved to dormant while it stays open.

    Dormant
  2. Aug 19, 2026

    Nihon Kotsu issued its fourth official notice on the incident, confirming for the first time that some of the files it held had actually leaked outside the company, though it said the full scope was still under investigation with outside security specialists helping with recovery.

    Activeinternet.watch.impress.co.jp
  3. Aug 18, 2026

    A Japanese tech outlet reported that AiLock's dark web leak page still listed the claimed 2.9 terabytes of Nihon Kotsu data as "Coming Soon" and had posted a partial file list. The report said the list reportedly includes drivers' internal disciplinary records for offenses like drunk driving and hit and run, possible SQL Server database backup files, and dashcam passwords apparently stored as plain text. None of this has been independently confirmed as genuine by the company.

    Activeitmedia.co.jp
  4. Aug 5, 2026

    No new confirmed activity reported, so this incident moved to dormant while it stays open.

    Dormant
  5. Jul 15, 2026

    The ransomware group AiLock publicly claimed the attack and threatened to leak stolen data if not paid.

    Activeransomware.live
  6. Jul 11, 2026

    Nihon Kotsu detected unauthorized access to its internal systems and shut down affected IT infrastructure, taking its taxi dispatch system offline.

    Emergingthecyberexpress.com

Sources

Related reports