Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

0
Medium
Vulnerability
Published: 07/24/2026 (07/24/2026, 17:50:37 UTC)
Source: Bleeping Computer

Description

Hackers have been compromising Wi-Fi gateway devices at hotels and conference centers by changing their DNS settings to redirect users to fake Microsoft 365 login pages. This campaign, active since at least June 2026, targets traveling employees across multiple industries globally. The attackers register lookalike domains to host phishing portals and use techniques that can bypass multi-factor authentication by exploiting the Microsoft device-code authentication flow. Some attempts to abuse WPAD were observed but not confirmed successful. The attack exploits weakly protected or vulnerable Wi-Fi gateway management interfaces. Recommended mitigations include using full-tunnel VPNs, encrypted DNS in strict mode, disabling WPAD, and disabling device-code authentication flow when not needed.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/24/2026, 18:07:16 UTC

Technical Analysis

This threat involves attackers gaining administrative access to Wi-Fi gateway devices at hotels and conference centers, likely through exploitation of weak or exposed management interfaces such as SSH, SNMP, or web admin dashboards. Once access is obtained, attackers modify the DNS settings on these devices to redirect legitimate Microsoft 365 login requests to attacker-controlled phishing domains (e.g., m365-owa.com, owa-ms365.com). The phishing pages capture credentials and can also exploit the Microsoft device-code authentication flow to obtain OAuth tokens without stealing credentials or access tokens directly, effectively bypassing MFA. The campaign affects organizations in diverse sectors and multiple countries, including the U.S., India, and Saudi Arabia. Attempts to abuse WPAD were also observed but not confirmed successful. Using public DNS servers does not prevent this attack because the compromised gateway forges DNS requests before they reach the resolver. ReliaQuest recommends full-tunnel VPNs, encrypted DNS, disabling WPAD, and disabling device-code authentication flow in Microsoft Entra ID as mitigations.

Potential Impact

Successful exploitation allows attackers to hijack Microsoft 365 accounts of users connecting to compromised hotel or conference center Wi-Fi networks. This can lead to unauthorized access to sensitive business information, communications, and private documents. The attack bypasses multi-factor authentication by abusing the device-code authentication flow, increasing the risk of account compromise even for users with MFA enabled. The campaign is not sector-specific and targets traveling employees across multiple industries globally.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Meanwhile, ReliaQuest recommends using an always-on, full-tunnel VPN and encrypted DNS in strict mode to protect against DNS hijacking. Disabling WPAD is advised to prevent proxy auto-discovery abuse. Additionally, organizations should consider disabling the device-code authentication flow in Microsoft Entra ID if it is not required. Monitoring logs for suspicious activity on Wi-Fi gateways and securing management interfaces (e.g., disabling or hardening SSH, SNMP, and web admin dashboards) are prudent steps to reduce risk.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.bleepingcomputer.com/news/security/hackers-hijack-hotel-wi-fi-dns-to-steal-microsoft-365-accounts/","fetched":true,"fetchedAt":"2026-07-24T18:07:05.466Z","wordCount":820}

Threat ID: 6a63a9c99c2644c7f85afae0

Added to database: 07/24/2026, 18:07:05 UTC

Last enriched: 07/24/2026, 18:07:16 UTC

Last updated: 07/24/2026, 19:06:51 UTC

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses