The Signal
The retained coverage for this edition centers on a reported hotel and conference-center Wi-Fi credential-theft campaign. It pairs user-facing credential collection with an unconfirmed initial-access assessment. [1]
Must Know
Hotel Wi-Fi credential-theft campaign
What happened
ReliaQuest reported attackers compromising hotel and conference-center Wi-Fi gateways, then redirecting users to attacker-controlled Microsoft login pages to steal credentials; the activity was ongoing since at least June 2026. [1]
ReliaQuest assessed with low-to-medium confidence that exposed SSH, SNMP, or web administration interfaces combined with weak or reused administrator credentials provided initial access, but visibility constraints prevented confirmation. [1]
Why it matters
The reported activity affected devices across several U.S. cities, India, and Saudi Arabia, and targeted employees in finance, law, healthcare, energy, and retail. [1]