Cybersecurity firm ReliaQuest has uncovered an active campaign where attackers are compromising Wi-Fi gateways at hotels and conference centres to steal Microsoft 365 credentials. By modifying the DNS settings on captive portal appliances, the attackers redirect anyone on the network to convincing fake Microsoft login pages — no phishing email required. The campaign, linked to tradecraft associated with Russian espionage group APT28 (Fancy Bear), has been active since at least June 2026 and has hit organisations across financial services, legal, healthcare, and retail.
Why This Matters for Hospitality Venues
This is a pointed risk for Australian hospitality businesses. Hotels, conference centres, and licensed clubs run guest Wi-Fi networks that frequently share infrastructure with back-of-house systems — POS terminals, booking platforms, and staff email. When a guest Wi-Fi gateway is compromised, it’s not just travellers at risk. If your venue’s management or reservation staff connect through the same network segment, their Microsoft 365 accounts are exposed too.
Critically, ReliaQuest found the attack bypasses MFA in some cases by abusing Microsoft’s device-code authentication flow. That means strong passwords alone aren’t enough — the attacker gets a legitimate OAuth token without ever touching the user’s credentials.
We see this pattern regularly in hospitality environments across Sydney and regional NSW: a single gateway appliance handling both guest and operational traffic, with admin interfaces still on default credentials. It’s a common deployment shortcut that creates exactly the exposure this campaign exploits.
What to Check Now
Segment your networks. Guest Wi-Fi must be isolated from operational systems. If staff and guests share the same gateway hardware and VLAN, that separation needs fixing.
Audit gateway admin credentials. The most likely entry point is a weakly protected management interface — SSH, SNMP, or a web dashboard with default or reused passwords. Change them and enforce MFA on admin access.
Enforce encrypted DNS and VPN for staff. Any staff device connecting to shared or guest networks should use an always-on, full-tunnel VPN and DNS-over-HTTPS in strict mode. Plain-text DNS requests can be intercepted at the gateway before they ever reach your intended resolver.
How All IT Can Help
All IT works with hospitality groups across Sydney’s Northern Beaches, wider Sydney, and regional NSW to review Wi-Fi network architecture, segment guest and operational traffic, and harden access controls on network management interfaces. If your venue hasn’t reviewed its Wi-Fi security posture since the network was first deployed, that’s a practical starting point. See our hospitality IT services and cybersecurity services.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
