{"id":63253,"date":"2026-07-13T19:15:54","date_gmt":"2026-07-13T23:15:54","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=63253"},"modified":"2026-07-13T19:15:54","modified_gmt":"2026-07-13T23:15:54","slug":"nihon-kotsu-cyberattack-taxi","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/nihon-kotsu-cyberattack-taxi\/","title":{"rendered":"Nihon Kotsu shuts taxi systems after cyberattack"},"content":{"rendered":"<p>Japan&#8217;s largest taxi operator, <a href=\"https:\/\/www.nihon-kotsu.co.jp\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Nihon Kotsu<\/a>, has been forced to shut down critical systems including its dispatch infrastructure following a cyberattack detected early Saturday morning. The incident, which the company confirmed involved unauthorized external access and malware infection, has disrupted car hire, web booking, reservation management, telephone dispatch, and several internal systems that remain offline as of today.<\/p>\n<p>With annual group revenue of approximately $1 billion (\u00a5155 billion), Nihon Kotsu operates a fleet of 8,558 taxis and more than two thousand chauffeur vehicles, employing 18,228 people. The attack has directly impacted both business operations and essential mobility services across Japan&#8217;s major urban centers.<\/p>\n<h2>Attack Timeline and Systems Affected<\/h2>\n<p>The company detected the unauthorized access early Saturday and immediately implemented emergency countermeasures, including disconnecting affected systems to prevent lateral movement within the network. Despite these efforts, the taxi dispatch system \u2014 the operational backbone of the company \u2014 remains offline, forcing Nihon Kotsu to rely on alternative channels for service delivery.<\/p>\n<p>Customers have been directed to use the &#8216;GO&#8217; taxi app or visit nearby taxi stands to book Nihon Kotsu vehicles while system restoration continues. In a separate announcement, the firm confirmed that its &#8220;labor taxi&#8221; service \u2014 a specialized transport option for pregnant women nearing childbirth \u2014 has been suspended in Tokyo, Musashino City, Mitaka City, Tachikawa, Yokohama, and Saitama.<\/p>\n<h2>Investigation and Data Leak Status<\/h2>\n<p>Nihon Kotsu has engaged external cybersecurity experts to assist with forensic investigation and system recovery. The company states it is actively investigating the possibility that data may have been exfiltrated during the breach. At this stage, no data leak has been confirmed, but the firm has committed to providing updates through official announcements and personalized notifications should new information emerge.<\/p>\n<p>No ransomware group or extortion gang has yet claimed responsibility for the attack, leaving the motive and threat actor affiliation unknown at the time of writing.<\/p>\n<h2>Customer Advisory and Protective Measures<\/h2>\n<p>Nihon Kotsu has advised customers to exercise caution regarding suspicious communications purporting to originate from the company. Recipients should not open attachments or click links in such messages, as these may be phishing attempts exploiting the incident.<\/p>\n<p>For affected customers, immediate steps include monitoring financial accounts for unusual activity, enabling multi-factor authentication on any account linked to Nihon Kotsu services, and remaining vigilant against phishing emails that may reference the breach to extract personal information.<\/p>\n<h2>Broader Implications for Critical Transport Infrastructure<\/h2>\n<p>This incident underscores the vulnerability of essential transportation services to cyberattacks. When dispatch and reservation systems go offline, the operational impact extends beyond inconvenience \u2014 it affects mobility for vulnerable populations, including expectant mothers relying on specialized transport services. The attack on Nihon Kotsu serves as a reminder that transportation operators must prioritize network segmentation, robust backup procedures, and incident response readiness to maintain service continuity in the face of targeted cyber threats.<\/p>\n<h2>What Affected Users Should Do Now<\/h2>\n<p>Customers who have used Nihon Kotsu services should change passwords for any accounts associated with the company, enable multi-factor authentication where available, and monitor bank statements and credit reports for signs of fraud. Avoid engaging with any unsolicited emails or messages claiming to be from Nihon Kotsu, and report suspicious communications to the company through verified official channels. For users seeking taxi services in affected regions, the &#8216;GO&#8217; app offers a functional alternative while dispatch system restoration remains underway.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Japan&#8217;s largest taxi operator, Nihon Kotsu, has been forced to shut down critical systems including its dispatch infrastructure following a cyberattack detected early Saturday morning. The incident, which the company confirmed involved unauthorized external access and malware infection, has disrupted car hire, web booking, reservation management, telephone dispatch, and several internal systems that remain offline [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":74554,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/iili.io\/CEgmj2f.jpg","fifu_image_alt":"Nihon Kotsu shuts taxi systems after cyberattack","footnotes":""},"categories":[349],"tags":[],"class_list":["post-63253","post","type-post","status-publish","format-standard","has-post-thumbnail","category-articles"],"fifu_image_url":"https:\/\/iili.io\/CEgmj2f.jpg","fifu_image_alt":"Nihon Kotsu shuts taxi systems after cyberattack","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/63253","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=63253"}],"version-history":[{"count":0,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/63253\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/74554"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=63253"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=63253"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=63253"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}