This issue is essentially solved as much as it can be solved
It is solved by ensuring that the server dns name is set in our dns server and that the client is using the correct internal dns server for resolution.
In case of kempinski if true as said then it might be an insider job or a hacker was able to breach into their AD server i might presume....