Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Hotel Wi-Fi Hacks Expose Sensitive Business Info, Targeting Traveling Employees Worldwide

A sophisticated hacking campaign has been underway since at least June, compromising hotel and conference center Wi-Fi networks to steal Microsoft 365 accounts. The attackers, who appear to be highly organized and well-funded, are using a technique known as DNS hijacking to redirect users to fake login pages, potentially giving them access to sensitive business information.

The campaign affects organizations across various sectors, including financial services, professional services, legal, healthcare, energy, and retail. Cybersecurity company ReliaQuest has identified compromised Wi-Fi gateways in multiple US cities, as well as India and Saudi Arabia, serving corporate events. This means that traveling employees who use these networks are at risk of having their Microsoft 365 accounts compromised.

The attackers’ modus operandi is to gain administrator access to the Wi-Fi gateway, which they can do by exploiting weakly protected management interfaces or vulnerabilities. Once inside, they modify the DNS settings to redirect connections to legitimate domains to infrastructure under their control. This allows them to set up fake Microsoft login portals and trick users into entering their credentials.

ReliaQuest has identified at least four domains used by the attackers: m365-owa[.]com, owa-ms365[.]com, ms365-device[.]com, and ms365-live[.]com. When a user attempts to access a legitimate Microsoft login page, they are redirected to one of these fake portals, where they enter their credentials, potentially giving the attackers access to sensitive business information.

In some cases, the attackers have used a technique called device-code authentication, which allows them to bypass multi-factor authentication (MFA) protection without stealing any credentials or intercepting access tokens. This is particularly concerning as it shows that the attackers are highly sophisticated and well-resourced.

The researchers also observed attempts by the attackers to abuse Web Proxy Auto-Discovery (WPAD), a feature used by Windows to automatically configure proxy settings. However, they were unable to confirm whether these attacks were successful.

To protect themselves from this type of attack, ReliaQuest recommends using an always-on, full-tunnel VPN and encrypted DNS in strict mode. They also advise disabling WPAD, reviewing logs for suspicious activity, and disabling device-code authentication flow in Microsoft Entra ID when not needed.

This campaign highlights the importance of robust security measures, particularly when traveling or using public Wi-Fi networks. It’s essential to be aware of the risks and take steps to protect sensitive information. By being proactive and vigilant, organizations can reduce their exposure to these types of attacks and maintain the trust of their employees and customers.


Source: Bleeping Computer — 2026-07-24