Russian intelligence unit exploits hotel Wi-Fi to breach corporate accounts
Microsoft attributes a global campaign against hospitality networks to APT29, using custom malware to compromise Microsoft 365 credentials of traveling executives.
Microsoft has linked a sustained intrusion campaign targeting hotel and hospitality Wi-Fi infrastructure to Midnight Blizzard, the Russian Foreign Intelligence Service unit also tracked as APT29. The operation deploys custom malware on compromised hotel networks to harvest credentials from business travelers connecting to Microsoft 365 services.
The threat actor gains initial access to hotel Wi-Fi systems, then positions malware to intercept authentication traffic from guests. Targets include senior executives, government officials, and employees of organizations in defense, technology, and policy sectors. The campaign has been observed across multiple continents, with a concentration in Europe and North America.
Midnight Blizzard—responsible for the SolarWinds compromise and numerous espionage operations—appears to be exploiting the trust travelers place in hotel networks. Once credentials are captured, the group uses them to access corporate email, cloud storage, and internal communications. Microsoft has not disclosed the total number of compromised accounts but describes the campaign as active and global in scope.
- 01Traveling executives and government officials face credential theft via compromised hotel Wi-Fi
- 02Hospitality operators may face liability and regulatory scrutiny over network security failures
- 03Enterprises must reassess remote access policies for employees connecting from third-party networks
- 04VPN and zero-trust vendors gain leverage as hotel Wi-Fi becomes presumed-hostile infrastructure
Boston Scientific confirms cyberattack disrupting medical device shipments
The Massachusetts-based medical device manufacturer disclosed the incident in SEC filings Tuesday, warning of operational impact to its supply chain.
US sanctions Iranian nationals after UK power plant intrusion
Treasury action follows disclosure of cyber operation targeting British energy facility, marking coordinated transatlantic response to infrastructure threats.
Supply-chain attack embeds proxy botnet in Android car head units
Legitimate device-update app compromised to spread malware that turns in-vehicle systems into proxy nodes and ad-fraud platforms.