CyberDefenseMagazine

How Hackers Are Weaponizing Hotel Wi-Fi to Steal Corporate Microsoft 365 Accounts


How the Attack Operates

Threat actors are quietly hijacking hotel Wi-Fi gateways to reroute traveling executives to fake Microsoft 365 login pages, stealing corporate credentials without leaving a trace in their inbox.  In order to launch DNS poisoning attacks on business travelers, threat actors are breaking into Wi-Fi gateway devices and captive portal equipment at hotels and conference centers. Internet-facing management interfaces with weak or default passwords have allowed attackers to gain administrative access. Once inside, they change the gateway’s DNS settings so that when a visitor connects to the public Wi-Fi and attempts to access Microsoft 365 services, the gateway gives a malicious IP address instead of the legitimate one. Victims are then directed to fraudulent phishing websites built on lookalike domains such as m365-owa[.]com. Traditional email security solutions and certain endpoint defenses could miss the redirection since the alteration takes place at the network level rather than on the user’s device. 

Strategic Impact and Defense Measures

Because a single compromised gateway may target numerous individuals across industries like banking, law, and healthcare without requiring malicious files or software downloads, this strategy is especially successful. ReliaQuest claims that the tradecraft is very similar to methods previously linked to the Russian state-sponsored threat organization APT28, commonly called Fancy Bear. When victims input their login information on the phishing site, they may reveal their usernames and passwords as well as authenticated session tokens that may be used by attackers to go beyond multi-factor authentication in adversary-in-the-middle attacks. By mandating always-on, full-tunnel VPNs for staff devices, organizations may drastically lower this risk by assuring that DNS queries and web traffic are routed via reliable corporate infrastructure rather than depending on possibly hacked public Wi-Fi networks. 

Author Notes

ReliaQuest Threat Research Team. “DNS Poisoning Tactics Expand to Hospitality Wi-Fi.” ReliaQuest Threat Spotlight, July 23, 2026

About the Author

Carmen Estela is a Cybersecurity Research Analyst at Cyber Defense Magazine and a Women in Cybersecurity Award Candidate. She recently graduated with a Master of Science degree from the University of Central Florida and holds a Bachelor’s degree in Criminology from the University of Florida with certifications in Data Analytics and AI Fundamentals. She frequently speaks and volunteers at well-known industry gatherings, such as BSides Orlando and BSides Jax, where she offers her perspectives on emerging cyber trends. Carmen is committed to advancing the standards of governance, risk, and compliance within cybersecurity. She has also served as an adult protective investigator, police dispatcher, and legal intern, applying investigative skills across law enforcement, academic, and public service settings. 

Reach her online at [email protected]



Source link