Warning: Compromised Hotel Routers Send Users to Phishing Sites
ID: 01a27586-50fe-5f5b-9807-f6d362fc3838
STIX ID: report--01a27586-50fe-5f5b-9807-f6d362fc3838
Feed Name: KnowBe4 Blog
Threat Score
ReliaQuest observed a campaign where compromised hotel Wi‑Fi routers are used for DNS poisoning to redirect travelers to Microsoft 365 phishing/authorization pages that capture OAuth tokens (via the device-code flow), allowing attackers to gain MFA-satisfied access to accounts; activity has been seen across the U.S., India, and Saudi Arabia and affects multiple industries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
