A Russian state-aligned advanced persistent threat (APT) group, known as Midnight Blizzard, has been identified as the culprit behind a series of public Wi-Fi gateway hacking incidents. These attacks have resulted in the theft of Microsoft account credentials, primarily targeting hospitality organizations. The group's tactics involve compromising public Wi-Fi networks, allowing them to intercept and steal sensitive information. This shift in threat activity from criminal to state-aligned poses a significant concern, as it indicates a geopolitical motivation behind the attacks1. The targeting of Microsoft accounts suggests a sophisticated level of planning and execution, highlighting the group's capabilities. The use of compromised Wi-Fi networks as an attack vector also underscores the importance of securing these often-overlooked entry points. This development matters to security practitioners because it signals a change in the threat model, requiring a different approach to mitigate and respond to these types of attacks.