Summary
- Compromised hotel and conference-centre gateways can redirect connected devices without requiring a phishing email or endpoint exploit.
- ReliaQuest observed counterfeit Microsoft pages and limited activity involving WPAD and device-code authentication.
- Strict encrypted DNS, full-tunnel VPNs, phishing-resistant authentication, and controlled gateway administration can reduce the exposure.
Attackers are compromising hotel and conference-centre Wi-Fi gateways to redirect connected users towards counterfeit Microsoft authentication pages, moving credential theft from the inbox into infrastructure controlled by the venue or its technology supplier.
ReliaQuest said it has observed the activity since at least June 2026. The attackers obtain administrative access to captive-portal gateways and alter the systems responsible for assigning network settings, resolving domain names, and routing traffic.
Once the gateway is controlled, forged DNS responses can send users to attacker-operated infrastructure even when they attempt to reach a legitimate service. Every device relying on the compromised network may be exposed without opening an attachment, following a link in an email, or executing malicious code.
The investigated gateways returned attacker-controlled addresses for broad categories of DNS requests. ReliaQuest identified pages assessed with medium confidence to be imitating Microsoft 365 services, including domains designed to resemble Outlook Web Access and Microsoft login infrastructure.
The campaign has affected hospitality systems in several locations and generated traffic associated with organisations in finance, professional services, legal services, healthcare, energy, and retail. The published investigation does not establish a current number of UK or European victims.
ReliaQuest assesses with low-to-medium confidence that attackers may be reaching gateways through exposed management services, including web administration, SSH, and SNMP, combined with weak or reused credentials. That route has not been confirmed across every affected system.
The technical account also describes limited use of Web Proxy Auto-Discovery and device-code authentication. WPAD can direct a device through an attacker-controlled proxy, while abuse of a device-code flow can obtain an authenticated token when a user completes a legitimate Microsoft prompt initiated by the attacker.
Some elements resemble techniques previously associated with Russian state-linked operations, although ReliaQuest has not attributed the current campaign. The infrastructure and redirection behaviour differ from earlier reports, and the available evidence does not establish responsibility by APT28 or another named group.
Ordinary endpoint DNS settings do not necessarily provide protection. A device configured to use a public resolver may still send an unencrypted request through the hostile gateway, allowing the response to be intercepted or forged before it reaches the intended service.
A full-tunnel VPN carries DNS traffic inside the corporate tunnel, while strict DNS over HTTPS or DNS over TLS prevents the local gateway from returning a forged response. Encrypted DNS configured to fall back to plaintext can lose that protection when the hostile network interferes with the secure resolver.
Identity controls remain necessary because counterfeit authentication pages can reach users through other routes. Phishing-resistant authentication, including FIDO2 security keys and properly implemented passkeys, limits the value of captured passwords.
Conditional-access policies can examine device compliance, token risk, location, and unusual authentication sequences. Organisations should also assess whether device-code authentication remains necessary and disable it where possible, since a victim can authorise an attacker’s session while interacting with a genuine Microsoft page.
Hospitality operators and their technology providers control a separate part of the exposure. Gateway management interfaces should not be published unnecessarily, default credentials must be removed, supported firmware should be maintained, and remote administration needs access restrictions and monitoring.
Unexpected changes to DNS, DHCP, routing, proxy settings, or captive-portal content should generate an investigation. Venues also need to know which supplier administers each gateway, how access is recorded, and how compromised systems can be rebuilt without disrupting wider operations.
Travelling employees may follow established security guidance and still encounter hostile infrastructure when the network controls name resolution and routing. Encrypted transport, managed devices, phishing-resistant authentication, and limited trust in local connectivity reduce the authority given to a familiar-looking login page.




