Cybersecurity Firm Reports Hacked Public Wi-Fi Gateways Targeting Corporate Credentials
A cybersecurity firm, ReliaQuest, has identified a new cyber threat involving the hacking of public Wi-Fi gateway appliances at organizations with captive portal networks. This attack targets the Microsoft 365 accounts of traveling corporate employees. The hackers have been modifying DNS configurations of compromised small office/home office (SOHO) routers to redirect users to attacker-controlled infrastructure, facilitating credential theft. This activity, ongoing since at least June 2026, is similar to the FrostArmada campaign, previously attributed to APT28, a group linked to Russia's GRU. The attacks have been observed at shared venues such as hotels and conference centers across the US, India, and Saudi Arabia. The campaign is not sector-specific, affecting industries like financial services, healthcare, and retail.