All incidents

Hotel Wi‑Fi DNS poisoning campaign targets Microsoft 365 credentials

campaignopenJul 24, 2026 — Jul 26, 2026
Hotel WiFi attacks hijack Microsoft 365 logins, linked to APT28

HACKERS have been compromising hotel Wi‑Fi networks to steal Microsoft 365 credentials from business travellers, a campaign that researchers have linked to the Russian cyber‑espionage group APT28. SecurityAffairs reported the activity after analysing telemetry from multiple hospitality sites that showed repeated redirections to spoofed login pages. The theft of credentials gives attackers indirect access to corporate email, SharePoint sites and other Microsoft 365 services, enabling espionage and data exfiltration without triggering traditional phishing defences. What distinguishes this operation is that the manipulation occurs at the network layer, so victims do not receive any suspicious email and may believe they are connecting to a legitimate hotspot.

The intruders gain control of exposed router management interfaces by guessing or reusing weak administrative passwords, then alter the device’s DNS settings to redirect users to fraudulent login pages that mimic the genuine Microsoft 365 sign‑in screen. ReliaQuest explained that this technique requires no interaction with phishing emails and works even when users are vigilant about unsolicited messages. In addition to DNS hijacking, the attackers abuse the Windows Web Proxy Automatic Discovery (WPAD) protocol to force laptops to send traffic through attacker‑controlled proxies, allowing the capture of any unencrypted credentials or session tokens. By chaining these two methods they can harvest usernames, passwords and authentication tokens from unsuspecting guests who trust the hotel’s wireless service.

Because the attack relies solely on manipulating network services, victims may remain unaware that their credentials have been harvested until unusual activity appears in cloud logs. Infosecurity Magazine noted that the same routers are being targeted in the United States, India and Saudi Arabia, indicating a geographically broad effort rather than a narrowly focused intrusion. The campaign does not rely on a specific vulnerability identifier, as no CVE has been assigned to the underlying misconfiguration, highlighting the role of credential hygiene in device security. Analysts warn that the tactic could be replicated in other venues that offer public wireless access, such as conference centres and airports.

ReliaQuest analysts have linked the observed activity to earlier intrusions attributed to APT28, which historically used spear‑phishing and credential dumping to gain persistence in government and defence networks. The shift to network‑level redirection suggests the group is expanding its toolkit to exploit trusted environments where multi‑factor authentication may be bypassed via session token theft.

No additional threat actors have been publicly identified in connection with this specific wave of hotel‑Wi‑Fi abuse, but the tradecraft aligns with known Russian intelligence‑gathering patterns. The campaign’s persistence across multiple regions highlights the need for organisations to treat guest networks as potentially hostile zones.

Organisations should ensure that corporate devices always connect via a trusted virtual private network, which encrypts traffic regardless of the underlying network, and they should disable WPAD on endpoints where it is not required. Network administrators ought to rotate default credentials on guest‑facing routers, segment guest Wi‑Fi from internal networks and monitor DNS query logs for unexpected redirects.

Enforcing multi‑factor authentication for Microsoft 365 accounts adds a barrier that prevents stolen passwords from being used alone, while conditional access policies can block sign‑ins from unfamiliar locations. Regularly reviewing firewall rules and disabling remote administration interfaces on wireless hardware reduces the attack surface that intruders initially exploit.

Security teams should subscribe to threat‑intelligence feeds that announce newly compromised hospitality gateways and integrate those indicators into intrusion‑detection systems for rapid blocking. Users travelling for work must be trained to inspect the URL bar before entering credentials, looking for subtle misspellings or unexpected domains that indicate a spoofed page.

Applying the principle of least privilege to service accounts limits the damage if a token is captured, and logging all authentication attempts helps detect anomalous behaviour early. By combining network hardening, strong identity controls and continuous monitoring, businesses can mitigate the risk posed by this evolving Wi‑Fi based credential‑theft campaign.

Intelligence briefing updated Jul 27, 2026

Root sourcereliaquest.com
Timeline Coverage

Swipe to explore timeline