Washington Hotel (WHG Hotels/Fujita Kanko Inc.) in Japan disclosed a ransomware infection after attackers gained unauthorized access to multiple servers, impacting parts of its internal network. The intrusion was detected on February 13, 2026, around 22:00 local time, prompting IT staff to disconnect external/internet access to contain spread; the company also notified law enforcement, formed an internal task force, and brought in external cybersecurity experts to investigate root cause, scope, and recovery.
Initial findings indicate the attacker accessed various business-related data on affected servers, while the company said customer membership/loyalty data (including the “Washington Net” program) is likely unaffected because it is hosted/managed on separate third-party systems with no confirmed unauthorized access. Operational impact was described as limited, though some properties experienced temporary credit card terminal outages; broader guest services reportedly remained functional, and restoration is underway while the company evaluates potential business/financial impact. As of reporting, no ransomware group had publicly claimed the incident on monitored extortion sites.

See attribution, scope, and your downstream exposure.
5 events from the most recent confirmed update back to the earliest known activity.
As of the disclosures, restoration of affected systems was underway while the company assessed financial and business impact and continued investigating possible exfiltration. No ransomware group had publicly claimed responsibility for the attack on monitored extortion sites.
Around 2026-02-16 to 2026-02-17, Washington Hotel disclosed that it had suffered a ransomware attack and that business data on affected servers may have been exposed. The company said customer and loyalty program data were likely unaffected because they were hosted on separate third-party-managed systems.
Following the server compromise, some hotel properties experienced temporary credit card terminal outages and related service issues. Washington Hotel said guest services remained largely functional and that there was no major overall operational disruption.
After detecting the attack, IT staff disconnected affected servers and external network access to contain the breach. The company formed an internal task force, engaged external cybersecurity experts, and notified police to investigate the cause, scope, and possible data exposure.
On 2026-02-13 at about 22:00 local time, Washington Hotel detected unauthorized access to multiple servers in a ransomware incident. The intrusion affected parts of its internal network and led to confirmed access to business data on compromised systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecybersecuritynews.com
Open sourceteiss.co.uk
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.