In what appears to be a state-sponsored credential theft campaign, a group of network marauders has been targeting Wi-Fi gateways at hotels, conference centers, and other shared venues to hijack corporate travelers' accounts.

Once the threat actors control the Wi-Fi gateway, they quietly redirect users to attacker-controlled infrastructure to steal credentials, according to a report by ReliaQuest, a global security operations and threat response automation company.

According to ReliaQuest, the activity has been ongoing since at least June 2026.

The compromised devices investigated by ReliaQuest were appliances primarily used at hotels and other organizations running captive Wi-Fi services, explained the report authored by researchers Alexander Capraro, Jalen Vaughn, Daxton Wirth, Austin Ritchie and Connor Short.

The researchers said, with "low-to-medium confidence," that the attackers likely gained initial access through exposed management interfaces combined with weak or reused administrative credentials, although limited visibility into the compromised devices prevented them from confirming that assessment.