Briev
Live
Technology

Hotel Wi-Fi Networks Hijacked to Phish Microsoft 365 Credentials

Hackers have compromised Wi-Fi gateways in U.S. hotels and conference venues, redirecting users to counterfeit Microsoft 365 login pages and stealing business credentials.

A campaign targeting hotel and conference-center Wi-Fi routers has been active since at least June, according to cybersecurity firm ReliaQuest. By gaining administrative control of the gateways, attackers modify DNS records so that requests for Microsoft 365 login pages are silently rerouted to fraudulent sites that look authentic. Compromised networks have been found in several U.S. cities and have affected employees from financial services, professional services, legal, health care, energy and retail firms, suggesting a focus on traveling workers rather than a single industry.

The fraudsters registered domains such as m365-owa.com and ms365-live.com to harvest credentials, and in some cases used a device-code authentication flow that can issue a valid OAuth token without the victim’s password. About one-third of the incidents also tried to abuse Windows’ WPAD feature to deliver a malicious proxy configuration, though the impact of those attempts is unclear. ReliaQuest warns that switching to public DNS alone won’t stop the attack, and recommends encrypted DNS, full-tunnel VPNs, cellular hotspots, careful URL verification and disabling unnecessary Microsoft Entra ID device-code authentication.

Why it matters

Traveling employees risk credential theft and broader corporate breaches when using compromised hotel Wi-Fi.

In this story

hotel Wi-FiphishingMicrosoft 365DNS hijackingcredential theftWPADfull-tunnel VPNmultifactor authenticationbusiness travelers