Full Report
このたび、当社の一部サーバーが第三者による不正アクセス及びランサムウェアによる感染被害を受けましたのでお知らせいたします。 当社は、本件発生を受け対策本部を設置のうえ、外部専門家の助言を受けながら、原因究明と被害状況の確認、情報流出の有無などの調査、ならびに復旧への対応を進めております。 被害の全容究明には今しばらくの時間を要する見込みですが、現時点で判明しております内容については下記の通りです。 お客様ならびに関係者の皆様には、多大なるご心配とご迷惑をおかけいたしますことを、深くお詫び申し上げます このたび、当社の一部サーバーが第三者による不正アクセス及びランサムウェアによる感染被害を受けましたのでお知らせいたします。 当社は、本件発生を受け対策本部を設置のうえ、外部専門家の助言を受けながら、原因究明と被害状況の確認、情報流出の有無などの調査、ならびに復旧への対応を進めております。 被害の全容究明には今しばらくの時間を要する見込みですが、現時点で判明しております内容については下記の通りです。 お客様ならびに関係者の皆様には、多大なるご心配とご迷惑をおかけいたしますことを、深くお詫び申し上げます。
Analysis Summary
# Incident Report: Ransomware Infection at Washington Hotel Corp.
## Executive Summary
On February 13, 2026, Washington Hotel Corporation detected a cyberattack involving unauthorized access and ransomware infection on several of its internal servers. The company immediately disconnected external network access to contain the threat and is currently working with law enforcement and external experts to investigate potential data exfiltration and restore operations.
## Incident Details
- **Discovery Date:** February 13, 2026, 22:00 JST
- **Incident Date:** February 13, 2026
- **Affected Organization:** Washington Hotel Corporation (Japan)
- **Sector:** Hospitality / Tourism
- **Geography:** Japan (Headquarters and various hotel locations)
## Timeline of Events
### Initial Access
- **Date/Time:** Prior to or on February 13, 2026, 22:00
- **Vector:** Unauthorized access (Specific method under investigation)
- **Details:** Attackers gained entry to a portion of the company’s server infrastructure.
### Lateral Movement
- The attackers moved through the internal network to compromise "some servers," leading to a ransomware deployment.
### Data Exfiltration/Impact
- **Operational Impact:** Ransomware encrypted data on affected servers. Some hotel locations experienced failures with credit card processing terminals.
- **Data Risk:** Unauthorized access to various business data stored on servers was confirmed. Investigation into whether this data was exfiltrated is ongoing.
### Detection & Response
- **2026/02/13 22:00:** Detection of unauthorized access and system intrusion.
- **Immediate Action:** Disconnection of external networks to prevent further spread.
- **2026/02/14:** Establishment of an internal Response Headquarters; notification to police and external security experts.
## Attack Methodology
- **Initial Access:** Unauthorized access (under investigation).
- **Persistence:** Not disclosed.
- **Privilege Escalation:** Not disclosed.
- **Defense Evasion:** Not disclosed.
- **Credential Access:** Not disclosed.
- **Discovery:** Not disclosed.
- **Lateral Movement:** Not disclosed.
- **Collection:** Access to business data confirmed.
- **Exfiltration:** Currently under investigation.
- **Impact:** Ransomware encryption and disruption of credit card payment terminals.
## Impact Assessment
- **Financial:** Impact on business performance is currently being assessed.
- **Data Breach:** Compromise of internal business data. Note: The "Washington Net" customer database is managed on a separate third-party server and is currently reported as unaffected.
- **Operational:** Disruption to credit card processing at certain hotel locations; however, overall hotel operations continue.
- **Reputational:** Public apology issued; potential loss of customer trust regarding data security.
## Indicators of Compromise
- **Network indicators:** hxxps[:]//www[.]washingtonhotel[.]co[.]jp/ (Primary site remains operational for disclosure).
- **File indicators:** Specific ransomware file extensions or hashes not yet released.
- **Behavioral indicators:** Unusual late-night server activity; failure of credit card terminal connectivity.
## Response Actions
- **Containment measures:** Immediate isolation of external network connections.
- **Eradication steps:** Deployment of external forensic specialists to identify and remove the threat.
- **Recovery actions:** Ongoing coordination with system partners for early system restoration.
## Lessons Learned
- **Key takeaways:** Segmentation between customer databases (Washington Net) and general business servers successfully limited the scope of potential PII (Personally Identifiable Information) exposure in this instance.
- **What could have been done better:** The reliance on shared network infrastructure led to operational disruptions (credit card terminals) even if the primary hotel stay was unaffected.
## Recommendations
- **Prevention:** Implement multi-factor authentication (MFA) on all remote access points to prevent unauthorized entry.
- **Network Segmentation:** Further isolate IoT and payment processing devices (credit card terminals) from general business servers.
- **Monitoring:** Enhance 24/7 Managed Detection and Response (MDR) capabilities to identify lateral movement faster before ransomware deployment.