APT28-linked campaign hijacks hotel Wi-Fi for logins

A cyber espionage campaign linked to the APT28 group is targeting public Wi-Fi gateways in hotels to steal Microsoft 365 credentials from corporate travelers. By compromising captive portals, attackers redirect users to malicious sites to harvest login data without needing traditional phishing methods.
Why it matters
This sophisticated attack vector bypasses standard device security, posing a major risk to corporate data security for employees traveling internationally.
ReliaQuest has identified a campaign targeting public Wi-Fi gateways at hotels and conference centres to steal Microsoft 365 credentials from corporate travellers. The activity has been under way since at least June 2026.
Attackers compromised captive portal appliances that manage guest internet access, then altered their settings to redirect users to infrastructure under the attackers' control. The technique let threat actors harvest credentials without sending phishing emails or infecting users' devices.
Compromised gateways were found in several US cities, as well as in India and Saudi Arabia, mainly in hotel and hospitality settings. Traffic to those gateways came from organisations in financial services, professional services, legal, health care, energy and retail, suggesting the operation targeted travelling employees rather than a single sector.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in