An attacker combined a jailbroken instance of Anthropic’s Claude with an open-source penetration-testing tool to breach four hotel booking and property-management platforms operating in Thailand, Canada, South Africa, and Japan, stealing roughly 2.1 million guest records including names, emails, phone numbers, reservation dates, and payment details. The attacker bypassed the model’s safety guardrails by framing malicious queries as legitimate security audits rather than attacks. Researchers discovered the breach after finding a server the attacker had left publicly exposed, complete with attack documentation. The stolen reservation data is now at risk of use in targeted phishing campaigns against hotel guests across multiple countries.