Japan's largest taxi operator shuts down systems after a cyberattack
Nihon Kotsu, Japan's largest taxi operator, shut down internal systems after a cyberattack, disrupting parts of its operations while it investigates and recovers. Precautionary shutdowns like this are a common response to intrusions such as ransomware, aimed at containing an attacker and limiting damage while forensic work proceeds, though they also interrupt normal business. The incident fits a broader pattern of attacks against transportation and logistics providers, whose real-time operations and large customer bases make downtime costly and pressure on victims high. Full details, including whether customer data was accessed, were not yet available, but the disruption underscores how operational technology and business systems in transport are increasingly targeted.
- Check
- Transportation and logistics operators should review their ability to detect and contain intrusions quickly, test whether critical operations can continue during a systems shutdown, and confirm backups and incident-response plans are current.
- Affected
- Transportation and logistics providers whose real-time operations make downtime costly; attackers target them for disruption and leverage, and a breach can force a business-halting precautionary shutdown before data impact is known.
- Fix
- Segment operational and business systems, maintain tested offline backups and an incident-response plan, enforce phishing-resistant MFA on remote access, and rehearse continuing critical services during a partial or full systems shutdown.