Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Cybersecurity Threat Alert: Hotel Wi-Fi Hijacked to Steal Microsoft 365 Accounts

A disturbing trend has been unfolding in the cybersecurity world, with hackers exploiting hotel and conference center Wi-Fi networks to steal sensitive information from unsuspecting users. By hijacking DNS settings on these networks, attackers are redirecting users to fake Microsoft 365 login pages, compromising their credentials and potentially gaining access to valuable business data.

The campaign, which has been ongoing since at least June, targets organizations across various sectors, including financial services, professional services, healthcare, energy, and retail. Cybersecurity company ReliaQuest has identified compromised Wi-Fi gateways in multiple U.S. cities as well as regions such as India and Saudi Arabia, suggesting a global reach.

The attack chain begins with the threat actor gaining access to the hotel’s Wi-Fi gateway, likely through exploiting weakly protected management interfaces or vulnerabilities. Once inside, they modify the DNS settings to redirect legitimate connections to fake Microsoft login portals, registered under domains such as m365-owa[.]com and owa-ms365[.]com.

When users attempt to log in to their Microsoft 365 accounts, they are unknowingly routed to the attacker’s phishing pages, where they enter their credentials. In some cases, the attackers use a device-code authentication flow, which bypasses multi-factor authentication (MFA) protection without stealing any credentials or intercepting access tokens.

The researchers also observed attempts to abuse Web Proxy Auto-Discovery (WPAD), which could potentially route traffic from Windows apps through an attacker-controlled proxy. However, it’s unclear whether these attacks were successful.

ReliaQuest emphasizes that using public DNS servers such as Google’s 8.8.8.8 does not prevent this attack, as the gateway forges plain-text requests before they reach the intended resolver. To protect against these types of attacks, the company recommends using an always-on, full-tunnel VPN and encrypted DNS in strict mode.

In addition to these measures, security teams should review logs for suspicious activity, disable WPAD, and disable device-code authentication flow in Microsoft Entra ID when not needed. By taking proactive steps to secure their networks, organizations can reduce the risk of falling victim to this type of attack.

It’s a stark reminder that even seemingly innocuous hotel Wi-Fi connections can pose significant security risks. As we continue to rely on public networks for connectivity, it’s essential to remain vigilant and take necessary precautions to safeguard our sensitive information.


Source: Bleeping Computer — 2026-07-24