Back to Exposure Report
TransportationJuly 2026Japan

Nihon Kotsu

Tokyo's largest taxi company confirms systems compromise. Dispatch and booking infrastructure affected in attack on transportation operations.

Dispatch recordsBooking dataCustomer informationCorporate accounts
1

What happened?

Nihon Kotsu, Tokyo's largest taxi company, confirmed a cyberattack affecting dispatch and booking systems. The company operates thousands of taxis in Tokyo and surrounding areas, moving passengers across Japan's capital daily.

Transportation systems operate on availability. Taxis need dispatch. Passengers need pickup. System downtime means operational failure in real-time, creating pressure during incident response.

2

What data was actually inside?

Taxi booking and dispatch data reveals movement patterns. Where people go. When they travel. How often. For corporate accounts, it tracks employee travel. For individuals, it documents personal routines.

Location data over time creates surveillance-grade intelligence. Combined with corporate account information, it reveals business activities, meeting locations, and executive movements.

3

Who gets hurt and how?

Nihon Kotsu riders. Corporate account holders whose employee travel is tracked. Business travelers with recorded pickup and destination patterns. Anyone whose travel history now exists in attacker hands.

Corporate accounts are particularly sensitive. Business travel reveals which companies are meeting, where executives go, and when deals might be closing. Competitive intelligence from taxi records.

4

What did they think they were doing right?

Transportation companies invest in reliability. GPS tracking, digital dispatch, mobile booking, electronic payment—each convenience enables better service but also creates data.

The systems that make modern taxi service efficient also create comprehensive records. Every ride, every route, every payment—documented for operational and business purposes.

5

What did they not know about their own data?

How much historical ride data persisted? Booking records from years past? Corporate account histories tracking employee travel patterns? Transportation systems accumulate data across millions of trips over time.

Retention policies determine breach scope. If ride data from three years ago persists, it's in scope. Location history creates personal exposure that extends far beyond recent activity.

If your business runs on databases, you probably have similar records—customer data, credentials, financial information. Do you know what's actually in yours?

6

What does attribution look like the morning after?

Japan's Personal Information Protection Act requires breach notification. Corporate customers need assessment of their account exposure. Investigation continues to determine full scope.

Japan has faced increasing attacks on domestic infrastructure. Railways, hospitals, automotive suppliers, now transportation services. The pattern targets essential services.

7

What would have changed the outcome?

Data minimization for location and travel history—retaining only what's operationally necessary.

Transportation companies need current operations data. They don't need years of historical ride patterns. Retention policies that expire old booking data limit what attackers can access. The organizations that protect location privacy are the ones that don't keep location data indefinitely.

Nihon Kotsu found out the hard way.

Your team could spend the next 6 months rebuilding systems, notifying customers, and answering legal questions. Or you could spend 24 hours finding out what's actually at risk.