logo

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

ID: d9340d71-22a5-51ba-ac91-64c3e2fc3ff6

STIX ID: report--d9340d71-22a5-51ba-ac91-64c3e2fc3ff6

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-07-24

Date Updated: 2026-07-24

Author: Bill Toulas

...
...

ReliaQuest has identified an ongoing global campaign where attackers change DNS on compromised hotel and conference Wi‑Fi gateways to redirect users to fake Microsoft 365 login pages (including use of device‑code OAuth flows to bypass MFA), affecting organizations across multiple sectors and regions; investigators found attacker‑registered phishing domains, attempted WPAD abuse, and recommend mitigations such as full‑tunnel VPN, encrypted DNS in strict mode, disabling WPAD, and disabling Device Code authentication when not required.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.