A cybersecurity vendor says a suspected Russia-linked spying campaign is using compromised Wi-Fi gateways at hotels and conference centers to steal account credentials from guests. The activity appears aimed at corporate employees who connect to these networks while traveling for work.
According to the report, the attackers are not just trying to capture usernames and passwords. They are also seeking authentication tokens, which can help intruders access services even after a login session has started. Microsoft 365 accounts are said to be a key focus, making the campaign especially concerning for businesses that rely on cloud email and productivity tools.
The operation highlights how hotel and event venue internet connections can become attractive targets for cyber-espionage. If attackers control or manipulate the Wi-Fi gateway, they may be able to intercept traffic or direct users into handing over sensitive login details without realizing the network has been tampered with.
For companies, the incident is another reminder that employee travel can create added security exposure. Public and semi-public networks at hotels and conference centers are convenient, but they can also become a weak point when threat actors use them to go after corporate identities and access tokens.