logo

Hackers Hijack Hotel Wi-Fi DNS to Steal Microsoft 365 Accounts

ID: ea327ec4-54e3-5218-8202-f997d506f48c

STIX ID: report--ea327ec4-54e3-5218-8202-f997d506f48c

Feed Name: CosmicBytez Labs

Threat Score
70/100

Date Published: 2026-07-26

Date Updated: 2026-07-26

...
...

## Executive Summary Attackers are compromising DNS configurations on hotel and conference Wi‑Fi equipment to redirect Microsoft 365 login traffic to realistic spoofed portals that capture credentials. The campaign—reported by BleepingComputer—leverages default credentials, unpatched firmware, physical access, or social engineering; stolen credentials enable BEC, data exfiltration, lateral movement, and persistence. Recommended mitigations include always using a VPN on public Wi‑Fi, deploying FIDO2/passkeys, enforcing conditional access and sign‑in risk policies, changing default admin credentials, segmenting guest networks, and monitoring DNS configurations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.