CYBERSECURITYTRACKER
TRACKING3,967 stories737 vuln stories
Permanent story citation

DNS Poisoning Tactics Expand to Hospitality Wi-Fi

The story is preserved as cited. Later corrections remain visibly typed and adjacent to the original snapshot.

← newsStory 3139

As cited

Citation snapshot as of .

threat intel

DNS Poisoning Tactics Expand to Hospitality Wi-Fi

Attackers have compromised public Wi-Fi gateways at hotels, conference centers, and similar venues to redirect traffic and steal Microsoft 365 credentials from traveling corporate employees through DNS poisoning tactics. The campaign, active since at least June 2026, affects organizations across financial services, healthcare, legal, energy, and retail sectors globally. ReliaQuest assesses the tradecraft mirrors tactics previously attributed to APT28 (also known as Fancy Bear and Forest Blizzard), a Russian military intelligence group.

Why it matters: Traveling employees connecting to public Wi-Fi at hotels and conferences face credential theft without device compromise or phishing; security teams should enforce always-on, full-tunnel VPN as the primary control to route all DNS traffic through corporate infrastructure and stop this attack vector.

Source published
First seen by Cybersecurity Tracker

Source attribution