Attackers hijack hotel Wi‑Fi to steal Microsoft 365 logins
🔒 Since at least June, researchers observed threat actors compromising captive Wi‑Fi gateways at hotels and venues to redirect traffic and harvest Microsoft 365 credentials. ReliaQuest found attackers gain admin access to portal appliances via exposed interfaces or weak credentials, then poison DNS responses to point users to attacker-controlled endpoints. The technique bypasses device-level protections and can affect employees from multiple sectors, while DNSSEC or changing resolvers alone offers limited protection. ReliaQuest recommends full‑tunnel VPNs, conditional access, encrypted DNS, and hardening PAC/WPAD settings to mitigate the risk.
