Nihon Kotsu shuts taxi systems after cyberattack

Nihon Kotsu, Japan's largest taxi operator, shuts down dispatch systems after a cyberattack, disrupting services for millions.

By Central
The cyberattack on Nihon Kotsu has forced the suspension of the labor taxi service for pregnant women in major cities.
Highlights
  • Nihon Kotsu detected unauthorized external access and malware infection early Saturday morning.
  • The labor taxi service for pregnant women has been suspended in Tokyo, Yokohama, and several other cities.
  • No ransomware group has claimed responsibility for the attack as of the time of writing.

Japan’s largest taxi operator, Nihon Kotsu, has been forced to shut down critical systems including its dispatch infrastructure following a cyberattack detected early Saturday morning. The incident, which the company confirmed involved unauthorized external access and malware infection, has disrupted car hire, web booking, reservation management, telephone dispatch, and several internal systems that remain offline as of today.

With annual group revenue of approximately $1 billion (¥155 billion), Nihon Kotsu operates a fleet of 8,558 taxis and more than two thousand chauffeur vehicles, employing 18,228 people. The attack has directly impacted both business operations and essential mobility services across Japan’s major urban centers.

Attack Timeline and Systems Affected

The company detected the unauthorized access early Saturday and immediately implemented emergency countermeasures, including disconnecting affected systems to prevent lateral movement within the network. Despite these efforts, the taxi dispatch system — the operational backbone of the company — remains offline, forcing Nihon Kotsu to rely on alternative channels for service delivery.

Customers have been directed to use the ‘GO’ taxi app or visit nearby taxi stands to book Nihon Kotsu vehicles while system restoration continues. In a separate announcement, the firm confirmed that its “labor taxi” service — a specialized transport option for pregnant women nearing childbirth — has been suspended in Tokyo, Musashino City, Mitaka City, Tachikawa, Yokohama, and Saitama.

Investigation and Data Leak Status

Nihon Kotsu has engaged external cybersecurity experts to assist with forensic investigation and system recovery. The company states it is actively investigating the possibility that data may have been exfiltrated during the breach. At this stage, no data leak has been confirmed, but the firm has committed to providing updates through official announcements and personalized notifications should new information emerge.

No ransomware group or extortion gang has yet claimed responsibility for the attack, leaving the motive and threat actor affiliation unknown at the time of writing.

Customer Advisory and Protective Measures

Nihon Kotsu has advised customers to exercise caution regarding suspicious communications purporting to originate from the company. Recipients should not open attachments or click links in such messages, as these may be phishing attempts exploiting the incident.

For affected customers, immediate steps include monitoring financial accounts for unusual activity, enabling multi-factor authentication on any account linked to Nihon Kotsu services, and remaining vigilant against phishing emails that may reference the breach to extract personal information.

Broader Implications for Critical Transport Infrastructure

This incident underscores the vulnerability of essential transportation services to cyberattacks. When dispatch and reservation systems go offline, the operational impact extends beyond inconvenience — it affects mobility for vulnerable populations, including expectant mothers relying on specialized transport services. The attack on Nihon Kotsu serves as a reminder that transportation operators must prioritize network segmentation, robust backup procedures, and incident response readiness to maintain service continuity in the face of targeted cyber threats.

What Affected Users Should Do Now

Customers who have used Nihon Kotsu services should change passwords for any accounts associated with the company, enable multi-factor authentication where available, and monitor bank statements and credit reports for signs of fraud. Avoid engaging with any unsolicited emails or messages claiming to be from Nihon Kotsu, and report suspicious communications to the company through verified official channels. For users seeking taxi services in affected regions, the ‘GO’ app offers a functional alternative while dispatch system restoration remains underway.

Share This Article