INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Hackers Compromise Hotel Wi-Fi Gateways to Hijack Microsoft Accounts
| 2026-07-27 14:43 CRITICAL HIGH DATA BREACH
Executive Summary
AI-generated
Hackers have been compromising hotel and conference Wi-Fi gateways since at least June 2026, according to research by ReliaQuest. The attackers are targeting employees from various sectors, including finance, legal, healthcare, energy, retail, and professional services organizations in the US, India, and Saudi Arabia. Once compromised, these gateways can redirect users to fake Microsoft login pages without sending a phishing email or infecting their computers. This allows attackers to obtain valid access tokens even when multifactor authentication is completed on a genuine Microsoft page. The attack flow resembles earlier APT28 campaigns, which also targeted network gateways and DNS responses, but ReliaQuest did not directly attribute the new campaign to this group due to lack of shared infrastructure or technical connection.
Technical Mitigations AI-generated
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity.
• Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
ms•••••.com
ow•••••.com
m3•••••.com
ms•••••.com
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
APT28APT28
Target & Sectors
Global Scope
healthhealth
hospitalityhospitality
retailretail
Incident Timeline
June 2026
Attackers used similar tactics to earlier APT28 campaigns, including DNS manipulation and exploitation of Windows Web Proxy Auto-Discovery, to target Microsoft 365 accounts via compromised hotel Wi-Fi gateways.
Click on any entity below to view its context and source!
infrastructure
Microsoft 365
infrastructure
Windows
Some affected devices also attempted to use Windows Web Proxy Auto-Discovery, known as WPAD, to route application traffic through an attacker-controlled proxy.
threat_actor
APT28
Attack flow (Via ReliaQuest)
Techniques Resemble Earlier APT28 Campaigns
ReliaQuest found similarities between this operation and earlier router attacks associated with
APT28
, also called
Fancy Bear
and
Forest Blizzard
.
ReliaQuest did not directly attribute the new campaign to APT28 because it found no shared infrastructure, reused code or other firm technical connection.
For instance, the current operation targets hotel and conference Wi-Fi equipment,
while earlier APT28 reporting
focused on home and small-office routers.
2026/07/27
Hackers compromised hotel Wi-Fi gateways to redirect employees' connections and hijack their Microsoft 365 accounts.
Click on any entity below to view its context and source!
infrastructure
Microsoft 365
Hackers Compromise Hotel Wi-Fi Gateways to Hijack Microsoft 365 Accounts.
Tactical Metrics
Metrics
infrastructure
Microsoft 365
Affected Product
Click for context!
The Russian military intelligence group has previously been linked to DNS manipulation used to compromise Microsoft 365 accounts.
Hackers Compromise Hotel Wi-Fi Gateways to Hijack Microsoft 365 Accounts.
These were not Microsoft services, but names designed to resemble legitimate Microsoft 365 and Outlook addresses.
Metrics
infrastructure
Windows
Affected Product
Some affected devices also attempted to use Windows Web Proxy Auto-Discovery, known as WPAD, to route application traffic through an attacker-controlled proxy.
Intelligence Sources
HackRead
2026-07-27
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T06:51
Comprehensive Tactical Telemetry
Highly Correlated Entities
11x
organisation
Identified Entity
ReliaQuest
entity
5x
industry
Targeted Sector
Finance
sector
4x
source region
Origin Country
United States
country
2x
infrastructure
Affected Product
Microsoft 365
software
Contextual Telemetry
Context Block
5 METRICS
timeline
Temporal Reference
at least June 2026
date
general metric
Accounts
365
accounts
tactic
Cyber Operation Type
Phishing
tactic
tactic
MITRE ATT&CK Technique
T1090 - Proxy
technique
threat actor
APT Group
APT28
actor
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.