Hackers Hijack Hotel Wi-Fi DNS to Steal Microsoft 365 Accounts
ID: ea327ec4-54e3-5218-8202-f997d506f48c
STIX ID: report--ea327ec4-54e3-5218-8202-f997d506f48c
Feed Name: CosmicBytez Labs
## Executive Summary Attackers are compromising DNS configurations on hotel and conference Wi‑Fi equipment to redirect Microsoft 365 login traffic to realistic spoofed portals that capture credentials. The campaign—reported by BleepingComputer—leverages default credentials, unpatched firmware, physical access, or social engineering; stolen credentials enable BEC, data exfiltration, lateral movement, and persistence. Recommended mitigations include always using a VPN on public Wi‑Fi, deploying FIDO2/passkeys, enforcing conditional access and sign‑in risk policies, changing default admin credentials, segmenting guest networks, and monitoring DNS configurations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
