Feed›Threat Intelligence›Hackers use DNS poisoning on hotel Wi‑Fi to steal Microsoft ...
Threat IntelligenceCyber Insider
8.0 — CRITICAL

Hackers use DNS poisoning on hotel Wi‑Fi to steal Microsoft 365 accounts

📅 24 July 2026 at 14:02 UTC📰 Cyber InsiderView original source ↗
Hackers use DNS poisoning on hotel Wi‑Fi to steal Microsoft 365 accounts

Threat actors are compromising hotel and conference center Wi-Fi gateways to redirect travelers to fake Microsoft login pages and steal corporate accounts. The campaign has been active since at least June 2026 and appears to reuse techniques previously associated with the Russian state-backed hacking group APT28, although the researchers stopped short of attributing the activity … The post Hackers use DNS poisoning on hotel Wi‑Fi to steal Microsoft 365 accounts appeared first on CyberInsider.

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

Threat actors compromised hotel and conference center Wi-Fi gateways to redirect travelers to fake Microsoft login pages, stealing corporate accounts using DNS poisoning techniques associated with APT28 tradecraft.

⚙️Technical Details
Affected Systems
captive portal appliances at hotels and conference venues
Attack Vectors
DNS poisoningexploiting exposed management interfaces (SSH, SNMP, web administration panels)Windows' Web Proxy Auto-Discovery (WPAD) featureMicrosoft's device code authentication flow
💥Impact Assessment
Severity: high
Who Is at Risk
traveling employees of targeted organizations in finance, healthcare, legal services, energy, retail, and professional servicesSeverity: high
🛡️Recommended Actions
1enforcing always-on VPNs configured in full-tunnel mode
2disabling WPAD where unnecessary
3monitoring authentication activity for connections through unknown proxy hosts
📦Affected Products
captive portal appliances at hotels and conference venues

Read the full article

This is a curated summary. The complete article is available at Cyber Insider.

Read on Cyber Insider ↗
← Back to feed