
ReliaQuest
US security operations firm that assessed a hotel-router credential-theft campaign without naming a state actor.
ReliaQuest reported on 23 July 2026 that compromised hotel WiFi routers redirect guests to fake Microsoft 365 logins, assessing the route at low-to-medium confidence and naming no state actor.
Last refreshed: 3 August 2026 · Appears in 1 active topic
Timeline for ReliaQuest
Assessed the router-compromise route at low-to-medium confidence without naming APT28
Cybersecurity: Threats and Defences: One firm hedged, heise online named APT28Documented hotel router DNS poisoning redirecting guests to fake Microsoft 365 pages
Cybersecurity: Threats and Defences: Hotel WiFi steers guests to fake loginsBackground
ReliaQuest is a US security operations firm. On 23 July 2026 it reported that compromised hotel WiFi routers were answering guest lookups with counterfeit Microsoft 365 sign-in pages via DNS poisoning, redirecting travellers without any phishing email or software installed on their device, with affected devices found across several American cities plus India and Saudi Arabia.
The firm's own assessment was notably restrained: it held the intrusion route at low-to-medium confidence, named no state actor, and cited only tradecraft overlap with an internal cluster it tracks as FrostArmada, while explicitly noting that the current activity differs from that cluster's prior behaviour. Four days later, heise online reported that Russian state attackers, naming APT28 directly, ran the campaign, a firmer claim ReliaQuest itself did not make.
That gap between ReliaQuest's hedged assessment and heise online's named attribution is the more notable fact about ReliaQuest's role on this beat than the campaign itself.