
QR-PDF Phishing Hits M365, MFA Bypass Surges
Cisco Talos Incident Response reports that phishing drove initial access in over half of Q2 2026 cases, often using QR codes in PDF attachments and trusted…
Researchers reported an ongoing campaign where attackers compromise hotel and conference venue Wi‑Fi routers and quietly redirect visitors’ web traffic through attacker-controlled systems. This can lead to corporate usernames and passwords being captured even when the victim does not click a phishing link, because the network itself is manipulated.
Researchers described an ongoing campaign in which attackers compromise Wi-Fi routers at hotels and conference venues. Once they have access, the attackers modify router configurations to enable DNS poisoning, redirecting web traffic for legitimate domains through attacker-controlled infrastructure. This lets them intercept and capture corporate usernames and passwords when a visitor signs into normal-looking web services while connected to the compromised network.
The activity has been observed across multiple countries, and the tradecraft has been described as similar to campaigns linked to APT28. The most notable element is that this attack does not depend on a victim clicking a malicious link or opening an attachment. Because the manipulation happens at the network level, a user can be compromised simply by connecting to the Wi-Fi and browsing as usual.
This technique is effective because it removes the usual signals people are trained to look for. There is no suspicious email, no unexpected attachment, and no obvious phishing message. Instead, the trust that travelers place in hotel and conference Wi-Fi networks becomes the exploited weakness. Employees who travel for work, including executives, sales staff, and consultants, are frequent users of these networks and often need to sign into corporate accounts quickly while away from the office.
Key warning signs include:
These red flags are subtle, which is part of why this technique is considered highly sophisticated. Anyone using hotel, conference center, airport, co-working, university, or healthcare Wi-Fi should be alert to these signals before entering any credentials.
Organizations can reduce exposure with a layered approach:
Together, these measures address both the technical exposure created by hostile networks and the human decision point where credentials are ultimately entered.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Attackers compromise routers at hotels and conference venues, then modify configurations to redirect legitimate web traffic through attacker-controlled infrastructure, capturing credentials when victims sign in on what appears to be a normal page.
No. Because the network itself is manipulated through DNS poisoning, a user can be compromised without clicking a phishing link, opening an attachment, or the attacker touching the device.
Recommended defenses include enforcing always-on full-tunnel VPN, auditing proxy authentication logs, disabling WPAD where not required, and training employees to validate URLs and certificates before entering credentials on public Wi-Fi.
The campaign primarily affects hospitality, but conference and event venues, airports, co-working spaces, universities, and healthcare facilities are also named as affected settings.
You’re at a hotel, on Wi‑Fi, no phishing email, no weird links… and your work password still gets stolen. Researchers found hotel and conference Wi‑Fi routers being hijacked. The DNS is poisoned so your traffic quietly detours through attacker systems, and a fake captive portal pops up saying, “Sign in to access Wi‑Fi, corporate login required.” Here’s the trick: that portal can impersonate your company login. But look at the address bar and certificate, on poisoned hotel Wi‑Fi it might be a weird domain and a certificate that doesn’t match your real identity provider, plus odd redirects while you browse. On hotel or conference Wi‑Fi, before you type any work username or password, pause and check the URL and certificate. If they’re not exactly right, stop and don’t log in.

Cisco Talos Incident Response reports that phishing drove initial access in over half of Q2 2026 cases, often using QR codes in PDF attachments and trusted…

Attackers are compromising hotel and conference center Wi‑Fi gateways and changing DNS settings so business travelers are silently redirected to fake Microsoft…

ReliaQuest reports attackers are compromising public Wi‑Fi “captive portal” gateways (such as in hotels and conference centers) and changing their DNS settings…

Authorities dismantled “Kratos,” a phishing-as-a-service platform used at scale to steal Microsoft account credentials and even bypass MFA by stealing session…

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials…

Researchers report attackers compromising hotel and venue Wi‑Fi “captive portal” gateways to redirect Microsoft 365 sign-ins to attacker-controlled lookalike…