A security investigation has exposed a massive booking platforms breach where a Russian hacker used artificial intelligence tools to compromise multiple accommodation companies.
Researchers discovered an exposed server belonging to the threat actor on April 16, 2026. This server contained detailed documentation of attacks targeting the hospitality sector.
Details of the Booking Platforms Breach
The booking platforms breach involved the use of HexStrike AI, which is an open-source tool. The attacker integrated this tool with Anthropic’s Claude assistant to execute the data theft.
The configuration files for Claude contained the personal email of the threat actor. This detail helped researchers identify the attacker as a Russian citizen.
Bypassing Artificial Intelligence Guardrails
The attacker bypassed safety guardrails by disguising the malicious activity as legitimate penetration testing. Consequently, the hacker generated at least 50 penetration test reports detailing target infrastructure and vulnerabilities.
The exposed files contained 2.1 million unique email addresses. This data represents a significant threat to the affected users who rely on secure tourism services.
Affected Accommodation Management Systems
Several companies fell victim to the booking platforms breach, including Thailand-based RoomScope. RoomScope suffered an exposure of 6.4 million booking records and 1.1 million unique email addresses.
Other affected entities include Canada-based IGMS, South Africa-based NebulaPMS, and Japan-based Staysee. Specifically, Staysee had over 31,000 payment records and 49,000 product records exposed.
NebulaPMS confirmed they learned of a potential breach in March 2026. The company has since taken steps to secure its systems.
“Subsequently, we have performed a number of additional pen tests and security scans and we continue to mitigate as and when we are made aware of any vulnerabilities.”
NebulaPMS Representative
Risks of Phishing for Travelers
Stolen data from the booking platforms breach enables highly targeted phishing campaigns. Attackers can use names, travel dates, and reservation numbers to craft convincing messages.
This incident highlights the growing need for stronger cybersecurity measures in the hospitality industry. Organizations must invest in better tools to protect customer data from sophisticated artificial intelligence threats.
Broader Threats to Hospitality Platforms
This incident is not an isolated event in the travel sector. In April 2026, researchers uncovered a massive operation siphoning data from Spanish and Austrian hospitality platforms.
Additionally, Booking.com recently warned customers about personal data exposure after unauthorized network access. These events show that accommodation platforms remain primary targets for cybercriminals worldwide.





