ATLAS · LIVE
ATLAS INDEX
Δ 24H
ACTIVE SOURCES20
HOTSPOTS20
TIME23:08:27 UTC
← All briefs
HIGHCyber IntelligenceTuesday, August 4, 2026

Russian intelligence unit exploits hotel Wi-Fi to breach corporate accounts

Microsoft attributes a global campaign against hospitality networks to APT29, using custom malware to compromise Microsoft 365 credentials of traveling executives.

Microsoft has linked a sustained intrusion campaign targeting hotel and hospitality Wi-Fi infrastructure to Midnight Blizzard, the Russian Foreign Intelligence Service unit also tracked as APT29. The operation deploys custom malware on compromised hotel networks to harvest credentials from business travelers connecting to Microsoft 365 services.

The threat actor gains initial access to hotel Wi-Fi systems, then positions malware to intercept authentication traffic from guests. Targets include senior executives, government officials, and employees of organizations in defense, technology, and policy sectors. The campaign has been observed across multiple continents, with a concentration in Europe and North America.

Midnight Blizzard—responsible for the SolarWinds compromise and numerous espionage operations—appears to be exploiting the trust travelers place in hotel networks. Once credentials are captured, the group uses them to access corporate email, cloud storage, and internal communications. Microsoft has not disclosed the total number of compromised accounts but describes the campaign as active and global in scope.

The rest of this brief is inside the platform

Continue reading. Free.

A free Atlas account unlocks the full briefing, the co-analyst, daily delivery to your inbox, and a sector-personalised feed.

Full brief
Implications, sources, methodology
Co-Analyst
Ask follow-ups on every brief
Sector feed
Briefs filtered to what matters to you
Implications
  • 01Traveling executives and government officials face credential theft via compromised hotel Wi-Fi
  • 02Hospitality operators may face liability and regulatory scrutiny over network security failures
  • 03Enterprises must reassess remote access policies for employees connecting from third-party networks
  • 04VPN and zero-trust vendors gain leverage as hotel Wi-Fi becomes presumed-hostile infrastructure
Source
BleepingComputer
https://www.bleepingcomputer.com/news/security/hotel-wi-fi-attacks-use-custom-malware-to-breach-microsoft-365-accounts/
Brief is editorial commentary by Atlas Intelligence based on the cited public reporting. Atlas does not reproduce source text. Verify primary source before action.
#apt29#midnight blizzard#hotel wi-fi#credential theft#microsoft 365#russia
Related Briefs