Hotel Wi-Fi Hacked: Microsoft 365 Accounts Stolen Through Fake Login Pages

The security firm ReliaQuest has documented an active campaign in which attackers take control of Wi-Fi routers and gateways in hotels and conference centers and change their DNS settings to redirect guests to fake Microsoft 365 login pages. For a small business without an in-house IT department, the risk is very real: a password entered on the wrong page grants access to the company’s emails and documents.

The mechanism is simpler than it seems. DNS is the Internet’s “phone book,” and if the Wi-Fi network gives you the wrong number when you ask for “Microsoft 365,” you’ll end up on a page that looks exactly like the real one but belongs to the attackers. Most often, the gateway is compromised because its administration interface is exposed to the internet and has a weak or default password. Once inside, the attackers change the DNS settings, and guests who connect and open Microsoft 365 are redirected to fake login portals hosted on domains that mimic the service (variants including “m365” and “owa”). A single compromised Microsoft 365 account can grant access to email, documents, and the company’s internal communications, and the campaign has targeted organizations in several countries and has been active since at least June. For an entrepreneur who travels or has employees on the road, the key takeaway isn’t “avoid Wi-Fi,” but “don’t entrust your password to a network you don’t trust”:

  • Don't sign in to Microsoft 365 on public Wi-Fi without checking the address in the browser bar—it must be login.microsoftonline.com or outlook.office.com, not a similar-looking variant.
  • Enable phishing-resistant authentication (passkey) or, at the very least, two-step verification; even if your password is stolen, your account will be harder to hack.
  • For sensitive tasks while on the go, use mobile data or a trusted VPN, not open Wi-Fi.
  • Don’t ignore your browser’s certificate warnings—they’re a clear sign that something isn’t right.
  • If you manage your own Wi-Fi access points: change the default passwords, remove the management interface from the internet, and periodically check the DNS settings.

For small businesses, a brief discussion with the team before the travel season and a few basic settings on their Microsoft 365 accounts are enough to shut the door on this type of attack.

Sources:

  • BleepingComputer | https://www.bleepingcomputer.com/news/security/hackers-hijack-hotel-wi-fi-dns-to-steal-microsoft-365-accounts/
  • SecurityAffairs | https://securityaffairs.com/196017/security/hackers-hijack-hotel-wi-fi-to-steal-microsoft-365-credentials.html
  • Hackread | https://hackread.com/hackers-hotel-wi-fi-gateways-hijack-microsoft-365-accounts/

This article was generated with AI assistance.

Request a quote

← All news