Hotel and Conference Wi-Fi Networks Hijacked to Steal Corporate Login Details

Criminals are quietly rewriting the internet directions on public Wi-Fi routers at hotels and conference centres, then catching employees' Microsoft 365 passwords mid-air. Researchers say the campaign has been running since at least June 2026.

ThreatVectr Newsdesk· 3 min read
A close-up photoreal shot of a laptop screen showing a blurred generic corporate login form, with a faint ghostly overlay of scrambled characters resolving into
Share

Key points

  • Criminals have been tampering with public Wi-Fi routers at hotels and conference centres across the US, India, and Saudi Arabia since at least June 2026.
  • The attack changes DNS settings (the address book that tells your device where websites live) to silently redirect users to fake Microsoft login pages.
  • Victims span financial services, legal, healthcare, energy, retail, and professional services firms, confirming no single industry is being singled out.
  • Cybersecurity firm ReliaQuest identified four attacker-registered domains used to serve fake Microsoft sign-in pages.
  • The campaign shares tactics with a previously documented Russian state-linked operation called FrostArmada, but key infrastructure details differ.

What actually happened?

Criminals broke into the gateway appliances, meaning the hardware boxes that run the sign-in screens you see when you connect to Wi-Fi at a hotel or airport, and rewrote their DNS settings. DNS (Domain Name System) works like a phone book for the internet: when you type a web address, your device asks a DNS server which numbered address to go to. By altering those settings, the attackers could silently send every user on that network to a fake Microsoft 365 login page instead of the real one.

The technique is called adversary-in-the-middle (AitM), where an attacker inserts themselves into the connection between a user and a legitimate service, reading or copying everything that passes through. Passwords typed into the fake page go straight to the criminals.

ReliaQuest, the cybersecurity firm that discovered the campaign, found traffic flowing to the tampered gateways from employees at companies across at least six industries. Shared venues hit include hotels and conference centres in the US, India, and Saudi Arabia.

Who is behind it?

No one has been definitively identified. The tactics are similar to a Russian state-linked operation called FrostArmada, which was previously attributed to APT28 (also known as Fancy Bear and Forest Blizzard), a hacking group believed to work for Russia's military intelligence service, the GRU. However, the attacker-registered domains and IP addresses used here do not match infrastructure seen in past APT28 activity.

ReliaQuest notes that applying DNS poisoning to redirect all users at once, rather than targeting specific individuals, points to a "less sophisticated or less careful actor" than APT28. The attackers may be reusing APT28 methods without being the same group.

Detail This campaign FrostArmada (APT28)
Active since June 2026 Previously documented
Entry point Captive portal Wi-Fi gateways Varied
Redirect method DNS poisoning of all users More selective
Target locations US, India, Saudi Arabia Not venue-specific
Infrastructure overlap None confirmed Known APT28 domains/IPs

What should travelling employees do right now?

Avoid typing work passwords into any login screen that appears after connecting to hotel or conference Wi-Fi. If you must connect, use your company's VPN (Virtual Private Network, a private encrypted tunnel that keeps your traffic away from the local network) before opening any work application.

Any employee who connected to public Wi-Fi at a hotel or conference centre in the affected regions since June 2026 and logged into Microsoft 365 should report it to their IT team immediately. Change your Microsoft 365 password from a trusted network. If your account uses multi-factor authentication (MFA), meaning a second confirmation step such as a code sent to your phone, review recent sign-in activity for anything unusual via the Microsoft account security portal.

© 2026 Threat Vectr