ReliaQuest published findings on 23 July showing compromised hotel WiFi routers and access points answering guest lookups with attacker-controlled addresses, steering travellers to counterfeit Microsoft 365 sign-in pages and collecting corporate credentials as they were typed 1. ReliaQuest, a US threat-detection firm, found the affected devices across multiple American cities, in India and in Saudi Arabia. The mechanism is DNS poisoning: the Domain Name System turns a typed web address into the machine address a browser actually connects to, and the hotel gateway is the resolver every joining device accepts automatically. One compromised box can therefore answer for every domain at once, and the guest sees the address they typed.
The travellers caught worked in financial services, legal services, healthcare, energy and retail, a spread ReliaQuest reads as a description of who travels rather than of who was selected 2. No phishing email arrives to be reported. No malware reaches the laptop, so the artefacts a corporate security team is instrumented to detect never come into existence. What the employer sees afterwards is a valid credential authenticating from an unfamiliar network, which looks exactly like a colleague signing in from a conference hotel.
Rewriting what a router tells the devices behind it is not a new manoeuvre on this beat; the same technique ran against home routers in April in a campaign attributed to Russian military intelligence . Hotels change the economics of it. A residential compromise yields one household, while a hotel gateway sits between a rotating population of business travellers and their employers' cloud tenancies, and the guest network is by design a place where unmanaged devices connect to strangers' infrastructure. ReliaQuest does not attribute the hospitality activity to the actor behind the April campaign, and who is running this one remains contested.
No procurement relationship exists between a traveller's employer and the hotel's network vendor, so the router cannot be patched, audited or scanned by the company whose credentials pass through it. The controls that remain sit on the traveller's side: a corporate VPN carrying all traffic, mobile tethering instead of the guest network, and sign-in methods that a counterfeit page cannot replay.
