Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts
Hackers have been compromising Wi-Fi gateway devices at hotels and conference centers by changing their DNS settings to redirect users to fake Microsoft 365 login pages. This campaign, active since at least June 2026, targets traveling employees across multiple industries globally. The attackers register lookalike domains to host phishing portals and use techniques that can bypass multi-factor authentication by exploiting the Microsoft device-code authentication flow. Some attempts to abuse WPAD were observed but not confirmed successful. The attack exploits weakly protected or vulnerable Wi-Fi gateway management interfaces. Recommended mitigations include using full-tunnel VPNs, encrypted DNS in strict mode, disabling WPAD, and disabling device-code authentication flow when not needed.
AI Analysis
Technical Summary
This threat involves attackers gaining administrative access to Wi-Fi gateway devices at hotels and conference centers, likely through exploitation of weak or exposed management interfaces such as SSH, SNMP, or web admin dashboards. Once access is obtained, attackers modify the DNS settings on these devices to redirect legitimate Microsoft 365 login requests to attacker-controlled phishing domains (e.g., m365-owa.com, owa-ms365.com). The phishing pages capture credentials and can also exploit the Microsoft device-code authentication flow to obtain OAuth tokens without stealing credentials or access tokens directly, effectively bypassing MFA. The campaign affects organizations in diverse sectors and multiple countries, including the U.S., India, and Saudi Arabia. Attempts to abuse WPAD were also observed but not confirmed successful. Using public DNS servers does not prevent this attack because the compromised gateway forges DNS requests before they reach the resolver. ReliaQuest recommends full-tunnel VPNs, encrypted DNS, disabling WPAD, and disabling device-code authentication flow in Microsoft Entra ID as mitigations.
Potential Impact
Successful exploitation allows attackers to hijack Microsoft 365 accounts of users connecting to compromised hotel or conference center Wi-Fi networks. This can lead to unauthorized access to sensitive business information, communications, and private documents. The attack bypasses multi-factor authentication by abusing the device-code authentication flow, increasing the risk of account compromise even for users with MFA enabled. The campaign is not sector-specific and targets traveling employees across multiple industries globally.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Meanwhile, ReliaQuest recommends using an always-on, full-tunnel VPN and encrypted DNS in strict mode to protect against DNS hijacking. Disabling WPAD is advised to prevent proxy auto-discovery abuse. Additionally, organizations should consider disabling the device-code authentication flow in Microsoft Entra ID if it is not required. Monitoring logs for suspicious activity on Wi-Fi gateways and securing management interfaces (e.g., disabling or hardening SSH, SNMP, and web admin dashboards) are prudent steps to reduce risk.
Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts
Description
Hackers have been compromising Wi-Fi gateway devices at hotels and conference centers by changing their DNS settings to redirect users to fake Microsoft 365 login pages. This campaign, active since at least June 2026, targets traveling employees across multiple industries globally. The attackers register lookalike domains to host phishing portals and use techniques that can bypass multi-factor authentication by exploiting the Microsoft device-code authentication flow. Some attempts to abuse WPAD were observed but not confirmed successful. The attack exploits weakly protected or vulnerable Wi-Fi gateway management interfaces. Recommended mitigations include using full-tunnel VPNs, encrypted DNS in strict mode, disabling WPAD, and disabling device-code authentication flow when not needed.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This threat involves attackers gaining administrative access to Wi-Fi gateway devices at hotels and conference centers, likely through exploitation of weak or exposed management interfaces such as SSH, SNMP, or web admin dashboards. Once access is obtained, attackers modify the DNS settings on these devices to redirect legitimate Microsoft 365 login requests to attacker-controlled phishing domains (e.g., m365-owa.com, owa-ms365.com). The phishing pages capture credentials and can also exploit the Microsoft device-code authentication flow to obtain OAuth tokens without stealing credentials or access tokens directly, effectively bypassing MFA. The campaign affects organizations in diverse sectors and multiple countries, including the U.S., India, and Saudi Arabia. Attempts to abuse WPAD were also observed but not confirmed successful. Using public DNS servers does not prevent this attack because the compromised gateway forges DNS requests before they reach the resolver. ReliaQuest recommends full-tunnel VPNs, encrypted DNS, disabling WPAD, and disabling device-code authentication flow in Microsoft Entra ID as mitigations.
Potential Impact
Successful exploitation allows attackers to hijack Microsoft 365 accounts of users connecting to compromised hotel or conference center Wi-Fi networks. This can lead to unauthorized access to sensitive business information, communications, and private documents. The attack bypasses multi-factor authentication by abusing the device-code authentication flow, increasing the risk of account compromise even for users with MFA enabled. The campaign is not sector-specific and targets traveling employees across multiple industries globally.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Meanwhile, ReliaQuest recommends using an always-on, full-tunnel VPN and encrypted DNS in strict mode to protect against DNS hijacking. Disabling WPAD is advised to prevent proxy auto-discovery abuse. Additionally, organizations should consider disabling the device-code authentication flow in Microsoft Entra ID if it is not required. Monitoring logs for suspicious activity on Wi-Fi gateways and securing management interfaces (e.g., disabling or hardening SSH, SNMP, and web admin dashboards) are prudent steps to reduce risk.
Technical Details
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/hackers-hijack-hotel-wi-fi-dns-to-steal-microsoft-365-accounts/","fetched":true,"fetchedAt":"2026-07-24T18:07:05.466Z","wordCount":820}
Threat ID: 6a63a9c99c2644c7f85afae0
Added to database: 07/24/2026, 18:07:05 UTC
Last enriched: 07/24/2026, 18:07:16 UTC
Last updated: 07/24/2026, 19:06:51 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.