As cited
Copy frozen at (site build).
threat intel
DNS Poisoning Tactics Expand to Hospitality Wi-Fi
Attackers have compromised public Wi-Fi gateways at hotels, conference centers, and similar venues to redirect traffic and steal Microsoft 365 credentials from traveling corporate employees through DNS poisoning tactics. The campaign, active since at least June 2026, affects organizations across financial services, healthcare, legal, energy, and retail sectors globally. ReliaQuest assesses the tradecraft mirrors tactics previously attributed to APT28 (also known as Fancy Bear and Forest Blizzard), a Russian military intelligence group.
Why it matters: Traveling employees connecting to public Wi-Fi at hotels and conferences face credential theft without device compromise or phishing; security teams should enforce always-on, full-tunnel VPN as the primary control to route all DNS traffic through corporate infrastructure and stop this attack vector.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
DNS Poisoning Tactics Expand to Hospitality Wi-Fi
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
DNS Poisoning Tactics Expand to Hospitality Wi-Fi
Adversaries have compromised public Wi-Fi gateways at hotels, conference centers, and other hospitality venues since at least June 2026 to perform DNS poisoning attacks that redirect traveling corporate employees to credential-harvesting infrastructure. The campaign, assessed to align with tactics used by APT28 (a Russian military intelligence group), targets users from multiple industries including financial services, healthcare, legal, and energy without requiring device-level access or phishing. Organizations can defend by enforcing always-on, full-tunnel virtual private network (VPN) on corporate devices to route all traffic through the corporate network before reaching the compromised gateway.
Why it matters: Corporate employees and their organizations are at immediate risk of Microsoft 365 account compromise when connecting to hotel and conference center Wi-Fi; practitioners should implement mandatory full-tunnel VPN policies as the primary mitigation.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
DNS Poisoning Tactics Expand to Hospitality Wi-Fi
Adversaries have compromised public Wi-Fi gateways at hotels, conference centers, and other hospitality venues since at least June 2026 to perform DNS poisoning attacks that redirect traveling corporate employees to credential-harvesting infrastructure. The campaign, assessed to align with tactics used by APT28 (a Russian military intelligence group), targets users from multiple industries including financial services, healthcare, legal, and energy without requiring device-level access or phishing. Organizations can defend by enforcing always-on, full-tunnel virtual private network (VPN) on corporate devices to route all traffic through the corporate network before reaching the compromised gateway.
Why it matters: Corporate employees and their organizations are at immediate risk of Microsoft 365 account compromise when connecting to hotel and conference center Wi-Fi; practitioners should implement mandatory full-tunnel VPN policies as the primary mitigation.
- Source published
- First seen by Cybersecurity Tracker