Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
3AUG

Hotel WiFi steers guests to fake logins

3 min read
16:08UTC

ReliaQuest reported on 23 July that compromised hotel routers are answering guest lookups with attacker-controlled addresses and steering travellers to counterfeit Microsoft 365 sign-in pages. No phishing email is involved and nothing lands on the laptop.

TechnologyAssessed
Key takeaway

Require a corporate VPN or mobile tethering for travelling staff; hotel gateways cannot be assessed.

ReliaQuest published findings on 23 July showing compromised hotel WiFi routers and access points answering guest lookups with attacker-controlled addresses, steering travellers to counterfeit Microsoft 365 sign-in pages and collecting corporate credentials as they were typed 1. ReliaQuest, a US threat-detection firm, found the affected devices across multiple American cities, in India and in Saudi Arabia. The mechanism is DNS poisoning: the Domain Name System turns a typed web address into the machine address a browser actually connects to, and the hotel gateway is the resolver every joining device accepts automatically. One compromised box can therefore answer for every domain at once, and the guest sees the address they typed.

The travellers caught worked in financial services, legal services, healthcare, energy and retail, a spread ReliaQuest reads as a description of who travels rather than of who was selected 2. No phishing email arrives to be reported. No malware reaches the laptop, so the artefacts a corporate security team is instrumented to detect never come into existence. What the employer sees afterwards is a valid credential authenticating from an unfamiliar network, which looks exactly like a colleague signing in from a conference hotel.

Rewriting what a router tells the devices behind it is not a new manoeuvre on this beat; the same technique ran against home routers in April in a campaign attributed to Russian military intelligence . Hotels change the economics of it. A residential compromise yields one household, while a hotel gateway sits between a rotating population of business travellers and their employers' cloud tenancies, and the guest network is by design a place where unmanaged devices connect to strangers' infrastructure. ReliaQuest does not attribute the hospitality activity to the actor behind the April campaign, and who is running this one remains contested.

No procurement relationship exists between a traveller's employer and the hotel's network vendor, so the router cannot be patched, audited or scanned by the company whose credentials pass through it. The controls that remain sit on the traveller's side: a corporate VPN carrying all traffic, mobile tethering instead of the guest network, and sign-in methods that a counterfeit page cannot replay.

Deep Analysis

In plain English

When you connect to hotel WiFi, your phone or laptop asks the hotel's router which internet address to use for a website you type in, like a phone book lookup. ReliaQuest, a cybersecurity firm, found that attackers have taken over some hotel routers and reprogrammed that phone book so travellers trying to reach Microsoft's login page get sent to a fake copy instead. The trick works without sending anyone a phishing email or infecting a laptop. Simply connecting to the WiFi and later trying to log into work email is enough, because the router itself, not your device, is doing the redirecting. ReliaQuest found affected hotels in multiple US cities, India and Saudi Arabia, hitting travellers from finance, law, healthcare, energy and retail firms.

Deep Analysis
Root Causes

The mechanism depends on a single architectural fact: a hotel gateway typically serves as the DHCP-assigned DNS resolver for every device that joins its guest network. Compromising the administrative interface on one device therefore controls DNS resolution for however many guests connect that day, with no need to compromise any individual laptop or phone.

Commercial hospitality WiFi is built for guest convenience, not endpoint security: open or shared-password networks, minimal segmentation between guest and back-office traffic, and administrative interfaces that ReliaQuest could not confirm were even exposed to the internet before compromise. The target sector's business model, frictionless connectivity for transient users, is structurally the same feature the campaign depends on.

What could happen next?
  • Risk

    Corporate travellers who use hotel WiFi for work logins face credential theft that standard phishing-awareness training won't catch, because no phishing message is involved.

  • Consequence

    Security teams may need to extend conditional-access and phishing-resistant MFA policies specifically to travel scenarios rather than treating hotel networks as equivalent to home broadband.

First Reported In

Update #12 · KEV deadlines fell from 14 days to three

ReliaQuest· 3 Aug 2026
Read original
Different Perspectives
Group-IB
Group-IB
Group-IB, headquartered in Singapore, documented on 19 March that The Gentlemen began inside Qilin's own affiliate programme and split from it over a payment dispute. Its analysis makes this window's leak-site tally readable as a fracture inside one ransomware operation rather than the arrival of an unknown crew.
ENISA
ENISA
ENISA placed EU drinking water and wastewater in its cyber risk zone for the first time on 28 May, finding one in three water entities had never run a risk assessment. CISA's 30 July advisory to American operators reads as the operational sequel to a gap European regulators had already documented two months earlier.
House of Lords and NCSC
House of Lords and NCSC
The Cyber Security and Resilience Bill sits at House of Lords committee stage, its amendment paper running to 23 July. Separately, the NCSC guidance CISA cited when directing water operators to disconnect controllers is version 1.0 from March 2024, a two-year-old British document doing operational work in an American alert published last week.
heise online
heise online
heise online reported on 27 July that Russian state attackers, named as APT28, ran the hotel WiFi credential-harvesting campaign. Its attribution is firmer than ReliaQuest's own hedged low-to-medium confidence assessment of the same intrusion, a difference in national reporting posture rather than a settled dispute over who is responsible.
CISA and ReliaQuest
CISA and ReliaQuest
CISA compressed remediation deadlines under BOD 26-04 while, in the same window, telling water and wastewater operators to disconnect internet-exposed controllers rather than patch them. ReliaQuest, investigating the hotel WiFi campaign, held its assessment of the intrusion route at low-to-medium confidence and declined to name a state sponsor.
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.