Canadian Cyber Security Journal
SOCIAL:
Filed under: Trends

APT28-Linked Campaign Poisons Hotel Wi-Fi DNS to Steal Microsoft 365 Credentials From Business Travelers — What Canadian Organizations Must Know

What Happened

ReliaQuest published research on July 24, 2026 describing an ongoing cyber espionage campaign targeting hotel and conference-centre Wi-Fi infrastructure. Attackers are gaining access to public Wi-Fi gateways — the routers and access controllers that manage internet connectivity for guests — by exploiting exposed management interfaces including SSH, SNMP, and web administration consoles, and by taking advantage of weak or reused administrator credentials.

Once inside a gateway, attackers modify DNS settings so every domain query from connected guests resolves to attacker-controlled IP addresses. Victims who attempt to open any website are silently directed to lookalike Microsoft 365 login pages that harvest credentials in real time. The campaign has been active since at least June 2026 and has been confirmed across hotels and conference venues in multiple US cities and internationally in India and Saudi Arabia. ReliaQuest researchers noted the tradecraft is consistent with APT28 (also known as Forest Blizzard and Fancy Bear), the Russian military intelligence unit linked to previous credential theft operations against travelling executives. Traffic from the compromised gateways came from organizations in financial services, professional services, legal, healthcare, energy, and retail — confirming broad targeting of corporate employees in transit.

Why This Matters for Canadian Organizations

Canadian business professionals travel extensively to the US and internationally for conferences, client meetings, and government engagements. Hotel and conference Wi-Fi is a routine part of that travel, and many corporate devices connect automatically without additional scrutiny. The DNS poisoning method is particularly difficult for end users to detect: the redirect happens at the network level before the browser receives a response, and the resulting fake login page appears to be at the correct URL until the victim examines the TLS certificate carefully.

The industries targeted in this campaign — financial services, legal, healthcare — overlap with sectors subject to OSFI Guideline B-13, PIPEDA, and provincial privacy legislation. A single set of M365 credentials harvested through a hotel Wi-Fi redirect gives an attacker access to the victim’s email, OneDrive documents, and SharePoint sites. For organizations that have not yet deployed phishing-resistant MFA such as FIDO2 hardware keys or certificate-based authentication, stolen credentials are sufficient for full account takeover. The CCCS has previously issued guidance on public Wi-Fi risks; this campaign confirms those risks are being actively exploited by state-level actors.

What to Do

Require employees to use a corporate VPN on any public Wi-Fi connection before accessing corporate systems, and enforce this through endpoint policy rather than relying on voluntary compliance. Deploy phishing-resistant MFA across all M365 and corporate applications — FIDO2 hardware security keys or Windows Hello for Business with certificate-based authentication are not susceptible to AiTM credential capture. Train travelling staff to verify TLS certificates before entering credentials on any login page encountered over hotel or conference Wi-Fi. IT teams should review Conditional Access policies to flag or block logins from hotel IP ranges or unusual geographies. Threat hunters should search for authentication events with unusual IP addresses or device fingerprints that correlate with known employee travel dates. Organizations handling sensitive client or regulated data should assess whether travel security policies require a formal risk update under PIPEDA or applicable sector requirements.

Source: BleepingComputer | ReliaQuest

Enjoy this article? Don’t forget to share.