CYBERSECURITYTRACKER
TRACKING7,811 stories in this site build1,697 vulnerability news stories in this site build
Permanent story citation

DNS Poisoning Tactics Expand to Hospitality Wi-Fi

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3139

As cited

Copy frozen at (site build).

threat intel

DNS Poisoning Tactics Expand to Hospitality Wi-Fi

Attackers have compromised public Wi-Fi gateways at hotels, conference centers, and similar venues to redirect traffic and steal Microsoft 365 credentials from traveling corporate employees through DNS poisoning tactics. The campaign, active since at least June 2026, affects organizations across financial services, healthcare, legal, energy, and retail sectors globally. ReliaQuest assesses the tradecraft mirrors tactics previously attributed to APT28 (also known as Fancy Bear and Forest Blizzard), a Russian military intelligence group.

Why it matters: Traveling employees connecting to public Wi-Fi at hotels and conferences face credential theft without device compromise or phishing; security teams should enforce always-on, full-tunnel VPN as the primary control to route all DNS traffic through corporate infrastructure and stop this attack vector.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

DNS Poisoning Tactics Expand to Hospitality Wi-Fi

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

DNS Poisoning Tactics Expand to Hospitality Wi-Fi

Adversaries have compromised public Wi-Fi gateways at hotels, conference centers, and other hospitality venues since at least June 2026 to perform DNS poisoning attacks that redirect traveling corporate employees to credential-harvesting infrastructure. The campaign, assessed to align with tactics used by APT28 (a Russian military intelligence group), targets users from multiple industries including financial services, healthcare, legal, and energy without requiring device-level access or phishing. Organizations can defend by enforcing always-on, full-tunnel virtual private network (VPN) on corporate devices to route all traffic through the corporate network before reaching the compromised gateway.

Why it matters: Corporate employees and their organizations are at immediate risk of Microsoft 365 account compromise when connecting to hotel and conference center Wi-Fi; practitioners should implement mandatory full-tunnel VPN policies as the primary mitigation.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

DNS Poisoning Tactics Expand to Hospitality Wi-Fi

Adversaries have compromised public Wi-Fi gateways at hotels, conference centers, and other hospitality venues since at least June 2026 to perform DNS poisoning attacks that redirect traveling corporate employees to credential-harvesting infrastructure. The campaign, assessed to align with tactics used by APT28 (a Russian military intelligence group), targets users from multiple industries including financial services, healthcare, legal, and energy without requiring device-level access or phishing. Organizations can defend by enforcing always-on, full-tunnel virtual private network (VPN) on corporate devices to route all traffic through the corporate network before reaching the compromised gateway.

Why it matters: Corporate employees and their organizations are at immediate risk of Microsoft 365 account compromise when connecting to hotel and conference center Wi-Fi; practitioners should implement mandatory full-tunnel VPN policies as the primary mitigation.

VendorsMicrosoft
Actorsapt28fancy bearforest blizzard
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary