The Signal

The retained coverage for this edition centers on a reported hotel and conference-center Wi-Fi credential-theft campaign. It pairs user-facing credential collection with an unconfirmed initial-access assessment. [1]

Must Know

Hotel Wi-Fi credential-theft campaign

Identity · Incident

What happened

ReliaQuest reported attackers compromising hotel and conference-center Wi-Fi gateways, then redirecting users to attacker-controlled Microsoft login pages to steal credentials; the activity was ongoing since at least June 2026. [1]

ReliaQuest assessed with low-to-medium confidence that exposed SSH, SNMP, or web administration interfaces combined with weak or reused administrator credentials provided initial access, but visibility constraints prevented confirmation. [1]

Why it matters

The reported activity affected devices across several U.S. cities, India, and Saudi Arabia, and targeted employees in finance, law, healthcare, energy, and retail. [1]

Sources (1)
  1. [1] Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Credentials

    securityaffairs · July 26, 2026

Daily security briefing · July 26, 2026 · Baitaphish