Skip to content
You can now search across every topic, entity and event.What's new
ReliaQuest
OrganisationUS

ReliaQuest

US security operations firm that assessed a hotel-router credential-theft campaign without naming a state actor.

ReliaQuest reported on 23 July 2026 that compromised hotel WiFi routers redirect guests to fake Microsoft 365 logins, assessing the route at low-to-medium confidence and naming no state actor.

Last refreshed: 3 August 2026 · Appears in 1 active topic

Timeline for ReliaQuest

#12 26 Jul

Assessed the router-compromise route at low-to-medium confidence without naming APT28

Cybersecurity: Threats and Defences: One firm hedged, heise online named APT28
#12 22 Jul

Documented hotel router DNS poisoning redirecting guests to fake Microsoft 365 pages

Cybersecurity: Threats and Defences: Hotel WiFi steers guests to fake logins
View full timeline →

Background

ReliaQuest is a US security operations firm. On 23 July 2026 it reported that compromised hotel WiFi routers were answering guest lookups with counterfeit Microsoft 365 sign-in pages via DNS poisoning, redirecting travellers without any phishing email or software installed on their device, with affected devices found across several American cities plus India and Saudi Arabia.

The firm's own assessment was notably restrained: it held the intrusion route at low-to-medium confidence, named no state actor, and cited only tradecraft overlap with an internal cluster it tracks as FrostArmada, while explicitly noting that the current activity differs from that cluster's prior behaviour. Four days later, heise online reported that Russian state attackers, naming APT28 directly, ran the campaign, a firmer claim ReliaQuest itself did not make.

That gap between ReliaQuest's hedged assessment and heise online's named attribution is the more notable fact about ReliaQuest's role on this beat than the campaign itself.

Common Questions
Did ReliaQuest say APT28 hacked hotel WiFi routers?
No. ReliaQuest assessed only tradecraft overlap with a cluster it calls FrostArmada, at low-to-medium confidence; heise online made the APT28 attribution, not ReliaQuest.Source: ReliaQuest / heise online
How were hotel WiFi routers used to steal Microsoft 365 logins?
Attackers with admin access to a hotel's gateway router forged DNS responses, redirecting guests to fake Microsoft 365 login pages and harvesting the credentials they entered.Source: ReliaQuest
What is FrostArmada?
ReliaQuest's internal name for a threat cluster it says shares tradecraft with the 2026 hotel-router DNS-poisoning campaign, though it also flags differences from that cluster's prior activity.Source: ReliaQuest