Hackers Compromise Hotel Wi-Fi Gateways to Hijack Microsoft 365 Accounts
ID: fef840b6-dcd7-5fab-b357-1cc60d2d0a50
STIX ID: report--fef840b6-dcd7-5fab-b357-1cc60d2d0a50
Feed Name: HackRead
ReliaQuest identified an active campaign (since at least June 2026) where attackers compromise hotel and conference Wi‑Fi gateways to alter DNS responses and redirect employees to Microsoft‑themed phishing pages (including domains like m365-owa.com and owa-ms365.com); the operation has impacted travelers from multiple sectors across several countries and has at times abused device‑code authentication and WPAD. Recommended mitigations include an always‑on full‑tunnel VPN and rejecting unexpected authentication prompts on public Wi‑Fi.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
