Japan’s largest taxi operator, Nihon Kotsu, suffered a damaging cyberattack on July 12, 2026, forcing the company to shut down critical systems and suspend dispatch services across multiple cities. The incident highlights the growing vulnerability of transportation infrastructure to cyber threats and raises concerns about operational resilience in essential public services.
What Happened: Nihon Kotsu Cyberattack Shuts Down Japan’s Largest Taxi Fleet
Nihon Kotsu, Japan’s largest taxi and chauffeur operator by group revenue, confirmed on July 13 that its internal systems were compromised through unauthorized external access involving malware infection. The attack occurred over the weekend, with early detection on Saturday morning.
Furthermore, the company immediately implemented emergency measures, including disconnecting affected systems to prevent further damage. Consequently, multiple services remain offline, including the taxi dispatch system, web booking platform, reservation management tools, telephone dispatch service, and several internal systems.
The company operates a fleet of 8,558 taxis and over two thousand chauffeur vehicles, employing 18,228 people. With annual revenue of approximately $1 billion (155 billion yen), the disruption affects one of Japan’s most critical transportation networks.
Technical Details of the Nihon Kotsu Cyberattack
According to Nihon Kotsu’s official statement, the attack vector involved unauthorized external access leading to malware infection on internal systems. The company has not disclosed the specific malware family or threat actor responsible. However, the incident shares characteristics common to ransomware and targeted intrusion campaigns against large enterprises.
In addition, the attack’s impact extended beyond standard IT infrastructure. The company confirmed that its “labor taxi” service, which provides critical transportation for pregnant women close to giving birth, was suspended in multiple areas. These areas include Tokyo, Musashino City, Mitaka City, Tachikawa, Yokohama, and Saitama.
Systems Affected by the Attack
- Taxi dispatch system (primary operations platform)
- Web booking and reservation management platforms
- Telephone dispatch service
- Internal corporate systems
- Labor taxi service for pregnant women in six regions
Attack Indicators and Response
Nihon Kotsu engaged external cybersecurity experts to assist with investigation and system recovery. The company is currently analyzing whether data was exfiltrated during the incident. At the time of writing, no ransomware group or extortion gang has publicly claimed responsibility for the attack.
Business and Operational Impact
The Nihon Kotsu cyberattack demonstrates how a single security incident can cripple essential public transportation services. The operational consequences are significant and multi-layered.
Immediate Operational Disruptions
- Passengers cannot book taxis through web or telephone dispatch channels
- Corporate accounts and reservation management are unavailable
- Pregnant women in six regions lost access to specialized labor taxi services
- The company redirected customers to the third-party GO taxi app or physical taxi stands
Financial and Reputational Impact
Nihon Kotsu generates roughly $1 billion in annual revenue. Therefore, even a brief service outage carries substantial financial implications. Moreover, the company’s reliance on external cybersecurity consultants and forensic experts indicates significant incident response costs.
Data Exposure Concerns
While Nihon Kotsu has not confirmed a data breach, the company stated it is investigating the possibility. The stolen data, if any, could include customer records, employee information, and operational data. Consequently, the company advised customers to avoid opening suspicious attachments or clicking links in communications claiming to originate from Nihon Kotsu.
Mitigation and Recommendations
Organizations operating critical infrastructure should treat the Nihon Kotsu cyberattack as a case study in preparedness and response.
Immediate Actions for Transportation and Critical Infrastructure
- Segment critical systems: Isolate dispatch, booking, and operational technology networks from general corporate IT to limit lateral movement.
- Maintain offline backups: Ensure backup copies of essential systems and data are stored offline and tested regularly for rapid restoration.
- Deploy endpoint detection and response (EDR): Monitor for anomalous behavior on servers and workstations, particularly in operational environments.
- Establish incident response playbooks: Pre-define communication channels, escalation paths, and system isolation procedures before an attack occurs.
- Conduct regular vulnerability assessments: Identify and patch exposed systems, particularly remote access and web-facing platforms.
Recommendations for Customers and Partners
- Verify any communications claiming to be from Nihon Kotsu through official channels
- Do not open attachments or click links in unsolicited messages
- Monitor for signs of identity theft or phishing attempts using personal information
- Use the GO taxi app or visit physical taxi stands for immediate transportation needs
Bottom line: The Nihon Kotsu cyberattack is a sobering reminder that transportation infrastructure remains a high-value target for threat actors. Organizations must prioritize network segmentation, offline backups, and incident response readiness to maintain service continuity when attacks occur.
Incident Summary
| Incident: | Nihon Kotsu Cyberattack |
| Target: | Nihon Kotsu Co., Ltd. (Japan’s largest taxi operator) |
| Affected Systems: | Taxi dispatch, web booking, telephone dispatch, internal systems, labor taxi service |
| Disclosure Date: | July 13, 2026 |
| Attack Date: | July 12, 2026 (detected early Saturday morning) |
| Attack Vector: | Unauthorized external access with malware infection |
| Patch Status: | Investigation ongoing; systems remain offline |
| Threat Actor: | Unclaimed; no group has publicly assumed responsibility |
References
- Nihon Kotsu Official Statement (Japanese), “Unauthorized Access Incident Notification,” July 13, 2026. https://www.nihon-kotsu-taxi.jp/news/260713/ (accessed July 14, 2026).
- Nihon Kotsu Official Statement (Japanese), “Labor Taxi Service Suspension Notice,” July 13, 2026. https://www.nihon-kotsu-taxi.jp/news/260713-2/ (accessed July 14, 2026).
- BleepingComputer, Gatlan, S. and Toulas, B., “Japan’s largest taxi operator shuts systems after cyberattack,” July 13, 2026. https://www.bleepingcomputer.com/news/security/japans-largest-taxi-operator-shuts-systems-after-cyberattack/ (accessed July 14, 2026).
- Nihon Kotsu Corporate Profile, “Company Overview.” https://www.nihon-kotsu.co.jp/about/profile/ (accessed July 14, 2026).