- Sources: ReliaQuest threat spotlight, Infosecurity Magazine
- Summary: ReliaQuest published a threat spotlight on 2026-07-23 describing attackers who take administrative control of hospitality Wi-Fi gateways and captive portals, then poison DNS so that authentication requests land on attacker infrastructure serving fake Microsoft 365 login pages. Secondary techniques include WPAD abuse for proxy redirection and abuse of the device-code authentication flow. ReliaQuest reports compromised gateways across multiple US cities and in India and Saudi Arabia, with affected traffic from financial services, professional services, legal, healthcare, energy, and retail organizations, and activity since at least June 2026. The report assesses the tradecraft as similar to APT28 but explicitly declines to attribute the campaign, citing technique overlap rather than shared infrastructure. Recommended controls are always-on full-tunnel VPN on corporate devices, disabling WPAD, auditing proxy authentication logs, and blocking the device-code flow through Conditional Access.
- Why it matters: The attack needs no phishing mail and no code on the target device, so endpoint controls and mail filtering do not see it and the only reliable break is forcing DNS and traffic through the corporate tunnel.
- Follow-up: Watch for named indicators, confirmation of the gateway compromise vector, and any vendor advisory from captive-portal appliance makers.
send feedback on this story