Hackers are targeting Wi-Fi networks at hotels and conference centers. They redirect users to fake Microsoft 365 login pages. This threatens business travelers who might connect to hotel Wi-Fi before a meeting. What looks like a standard Microsoft sign-in page could be a trap set by cybercriminals.
Hotel Wi-Fi Phishing Attack Details
ReliaQuest, a cybersecurity firm, reports that this attack has been ongoing since June. Compromised Wi-Fi gateways were found in multiple U.S. cities. The attackers appear to target traveling employees from various industries, not just one sector.
“CyberGuy” Kurt Knutsson explains these threats and offers protective tips at CyberGuyLive.com.
How the Attack Works
Hackers gain access to Wi-Fi gateways and alter the Domain Name System (DNS) settings. DNS translates website names into numerical addresses. Altering DNS settings redirects legitimate Microsoft login attempts to fake sites. Your device may display the hotel’s Wi-Fi network name, appearing safe but directing you to a hacker-controlled page.
Gateway Vulnerabilities
ReliaQuest has not pinpointed how hackers first access the gateways. Possible entry points include:
- Weak passwords
- Vulnerable web dashboards
- Poorly protected remote management services
Older Wi-Fi models with unpatched security flaws are also at risk. When hackers gain control, they can modify the DNS without affecting each guest’s device directly.
Fake Microsoft 365 Pages
Attackers have registered domains mimicking Microsoft’s services. These domains can fool users in a hurry. Hackers use them to collect login credentials. This could expose sensitive business information and allow hackers to impersonate employees.
Bypassing Multifactor Authentication (MFA)
Hackers sometimes use deceptive device code authentication. A fake Microsoft page might prompt device approval. Users who agree unknowingly issue a legitimate OAuth token to the hacker. This bypasses MFA because the system perceives valid approval.
WPAD Exploitation Attempts
About one-third of cases show attempts to abuse Web Proxy Auto-Discovery (WPAD). Hackers may inject malicious configuration files to control network traffic. Although not fully confirmed, the activity suggests risks beyond Microsoft login fraud.
Protection Measures
Travelling exposes you to these threats. Here’s how to stay safe:
- Use a full-tunnel VPN to encrypt internet traffic.
- Consider your phone’s hotspot for secure connectivity.
- Scrutinize Microsoft login web addresses carefully.
- Question unexpected device code requests.
- Keep your devices and browsers updated.
- Employ strong security software for extra defense.
- Ensure your company reviews Microsoft settings regularly.
An always-on VPN or phone hotspot can secure sensitive information. Never approve a Microsoft request you didn’t initiate. If something seems off, contact IT through trusted channels immediately.

Artificial Intelligence and Accountability
Congress Proposes AI Kill Switch for Major Systems
Enhancing Science Funding Policies
Trump’s Truth Social Service Sparks Discussion
Cyberattacks on Water Utilities in Multiple States
AI Models Challenge Cybersecurity: OpenAI and Anthropic Incidents Expose Risks