← Back to Tech & Science

Hackers Hijack Hotel Wi-Fi DNS to Steal Corporate Credentials in Global Campaign

Tech & ScienceAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

A sophisticated cyberattack campaign targeting travelers has exploited hotel wireless networks across the United States, India, and Saudi Arabia to steal Microsoft 365 login credentials. The operation involves hijacking Domain Name System (DNS) settings on public Wi-Fi access points, redirecting unsuspecting users to fraudulent login pages designed to mimic official corporate portals.

ReliaQuest identified the intrusion as part of a broader effort by threat actors potentially linked to APT28, also known as Fancy Bear. This group has historically been associated with Russian state-sponsored espionage activities. The attackers specifically targeted business travelers who rely on hotel internet connections for work while away from their offices. By manipulating DNS configurations, the hackers intercepted network traffic and forced users onto counterfeit Microsoft 365 authentication sites when they attempted to access email or cloud services.

The campaign was detected as of July 24, 2026, following an analysis of anomalous network behavior in major metropolitan areas across three continents. Once victims entered their usernames and passwords on the spoofed pages, the credentials were immediately captured by the attackers. The primary objective appears to be gaining unauthorized access to sensitive business information, internal communications, and private documents stored within corporate Microsoft 365 environments.

The attack vector highlights a significant vulnerability in public Wi-Fi infrastructure where users often trust network settings without verification. Unlike traditional phishing emails that require user interaction with malicious links sent via email, this method relies on the automatic redirection of web traffic at the network level. This approach allows attackers to compromise multiple devices simultaneously within a single hotel lobby or conference center.

Security experts note that the scope of the operation suggests a coordinated effort rather than isolated incidents. The geographic spread indicates an intent to maximize exposure among international business travelers, who frequently carry high-value data on their mobile devices and laptops. While no specific companies have been publicly named as victims in initial disclosures, the nature of the attack implies potential breaches across various sectors including finance, technology, and legal services.

The full extent of the compromised accounts remains unclear as organizations scramble to audit access logs and reset credentials for employees who traveled during the active period of the campaign. Questions remain regarding whether any data has already been exfiltrated or if the attackers are holding stolen credentials for future deployment. As investigations continue, cybersecurity firms advise travelers to avoid accessing sensitive corporate systems over public Wi-Fi networks until stronger authentication protocols can be verified.

Discussion

0 / 2000