INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Hackers Compromise Hotel Wi-Fi Gateways to Hijack Microsoft Accounts

| 2026-07-27 14:43 CRITICAL HIGH DATA BREACH
Executive Summary
AI-generated
Hackers have been compromising hotel and conference Wi-Fi gateways since at least June 2026, according to research by ReliaQuest. The attackers are targeting employees from various sectors, including finance, legal, healthcare, energy, retail, and professional services organizations in the US, India, and Saudi Arabia. Once compromised, these gateways can redirect users to fake Microsoft login pages without sending a phishing email or infecting their computers. This allows attackers to obtain valid access tokens even when multifactor authentication is completed on a genuine Microsoft page. The attack flow resembles earlier APT28 campaigns, which also targeted network gateways and DNS responses, but ReliaQuest did not directly attribute the new campaign to this group due to lack of shared infrastructure or technical connection.
Technical Mitigations AI-generated
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity. • Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc • Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

ms•••••.com
ow•••••.com
m3•••••.com
ms•••••.com
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
APT28APT28
Target & Sectors
Global Scope healthhealth hospitalityhospitality retailretail
Incident Timeline
‎June 2026
Attackers used similar tactics to earlier APT28 campaigns, including DNS manipulation and exploitation of Windows Web Proxy Auto-Discovery, to target Microsoft 365 accounts via compromised hotel Wi-Fi gateways.
infrastructure Microsoft 365
infrastructure Windows
threat_actor APT28
‎2026/07/27
Hackers compromised hotel Wi-Fi gateways to redirect employees' connections and hijack their Microsoft 365 accounts.
infrastructure Microsoft 365
Tactical Metrics
Metrics
infrastructure
‎Microsoft 365
Affected Product
Metrics
infrastructure
‎Windows
Affected Product
Intelligence Sources