AI-assisted espionage targets travelers and government personnel
A reported espionage campaign combines stolen data with operational control.
About these dates
Microsoft describes activity from February. Anthropic's campaign graphic spans March–August. These bounds do not establish individual intrusion dates or a campaign end. July 31 is the linked earlier public account.
The hospitality-network campaign
Microsoft traced an AI-assisted espionage campaign to Storm-2945, which it assesses is part of Midnight Blizzard. Its July account describes phishing activity from February and attacks on hotel and other guest networks from early May. The compromised networks redirected travelers toward credential theft and malware. Microsoft Threat Intelligence ↗
Microsoft reports compromised hospitality networks in several countries, but says the initial route into those networks remained under investigation. Its defensive response included published detection and mitigation guidance. Microsoft credits Anthropic and OpenAI for assistance, so these overlapping accounts are not wholly independent. Microsoft Threat Intelligence ↗
Related government intrusion
Anthropic, tracking related activity as GTG-20006, reports that attackers took over a North African government authority's central account server and exported its credential database. Anthropic ↗
Sources & attribution
- First-party report 10 Sept 2026Detecting and countering misuse of AI: September 2026 ↗
Anthropic. The developer is an interested party. Claims and attributions require their stated qualifications.
- First-party report 31 Jul 2026CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft ↗
Microsoft Threat Intelligence. Security-provider observations and attributed analysis. Collaboration credits limit claims of complete independence.