Microsoft has attributed a global attack campaign targeting hotel Wi-Fi networks to the Russian threat actor Midnight Blizzard (also known as APT29). The group uses compromised guest networks to specifically compromise travelers’ Microsoft 365 accounts.
Microsoft has publicly disclosed a campaign in which attackers use Wi-Fi infrastructure in hotels as a starting point to gain access to travelers’ Microsoft 365 accounts. The activity is attributed to the actor Midnight Blizzard, also known as APT29, which Western security agencies attribute to Russia’s foreign intelligence service SVR. The group deploys specially developed malware to gain access to guests’ end devices within the compromised networks.
For CISOs, the choice of attack vector is notable: hotel Wi-Fi networks are traditionally considered difficult to secure, often poorly segmented networks that are regularly used by employees on business trips or at conferences without additional protective measures. Successful access to a traveler’s Microsoft 365 account can give attackers access to corporate emails, calendars, file storage in SharePoint or OneDrive, and potentially other linked cloud services. Since Midnight Blizzard has historically targeted espionage primarily against government agencies, diplomacy, NGOs, and technology companies, a targeted selection of travelers from correspondingly interesting organizations is to be expected.
In practice, this means that policies for travelers should be tightened: the use of VPN connections when using public or semi-public Wi-Fi networks, mandatory multi-factor authentication for Microsoft 365 access, and conditional access policies that additionally scrutinize logins from unusual networks or locations significantly reduce the attack surface. Security teams should also review login logs for anomalies related to travelers and supplement awareness training with concrete guidance on the risks of hotel and conference Wi-Fi networks.
Microsoft attributes a campaign in which travelers’ Microsoft 365 accounts are attacked via compromised hotel Wi-Fi networks to the Russian actor Midnight Blizzard (APT29).
Source: www.bleepingcomputer.com · Published August 4, 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.