Washington Hotel Chain in Japan Hit by Ransomware
Hospitality chains store guest and payment data on connected systems, making rapid containment and network segmentation critical when ransomware strikes.
Breach Detected on Valentine's Day Weekend
Washington Hotel, a business-focused hospitality chain operating 30 locations across Japan with nearly 5 million guests annually, disclosed that it detected a ransomware attack on its servers on February 13, 2026, at 22:00 local time. IT staff immediately disconnected the affected servers from the internet to prevent the attack from spreading across the network.
The company established an internal task force the following day and engaged external cybersecurity experts and Japanese police to investigate the incident. Various business data on the compromised servers was accessed, though the full scope of what may have been exfiltrated remains under investigation.
Limited Operational Impact, Customer Data Likely Safe
The attack caused temporary disruptions including the unavailability of credit card terminals at some hotel locations, forcing staff to implement manual check-in procedures. However, the company reports that no significant long-term operational disruption occurred.
Washington Hotel stated that customer data, including the loyalty program's member information, is stored on separate servers managed by a different company, which has not reported any unauthorized access. The quick isolation of affected systems appears to have limited the damage.
Part of Broader Wave Targeting Japanese Enterprises
As of late February 2026, no ransomware group has publicly claimed responsibility for the Washington Hotel attack on monitored dark-web extortion portals. Security analysts note that the attack is part of a broader pattern of ransomware incidents targeting Japanese organizations in 2025 and 2026, including high-profile breaches at Nissan, Muji, Asahi, and NTT.
In the same timeframe, Japan's JPCERT/CC reported active exploitation of an arbitrary command injection vulnerability in Soliton Systems FileZen appliances, widely used file-sharing platforms in Japanese enterprises, though there is no direct evidence linking this vulnerability to the Washington Hotel incident.