As cited
Citation snapshot as of .
threat intel
DNS Poisoning Tactics Expand to Hospitality Wi-Fi
Attackers have compromised public Wi-Fi gateways at hotels, conference centers, and similar venues to redirect traffic and steal Microsoft 365 credentials from traveling corporate employees through DNS poisoning tactics. The campaign, active since at least June 2026, affects organizations across financial services, healthcare, legal, energy, and retail sectors globally. ReliaQuest assesses the tradecraft mirrors tactics previously attributed to APT28 (also known as Fancy Bear and Forest Blizzard), a Russian military intelligence group.
Why it matters: Traveling employees connecting to public Wi-Fi at hotels and conferences face credential theft without device compromise or phishing; security teams should enforce always-on, full-tunnel VPN as the primary control to route all DNS traffic through corporate infrastructure and stop this attack vector.
- Source published
- First seen by Cybersecurity Tracker