The bottom line: Russian actors use compromised hotel routers as intermediaries to steal Microsoft 365 login credentials from business travelers.
IT security researchers have identified compromised WiFi routers in hotels through which Russian attackers intercept Microsoft 365 login credentials. The approach demonstrates a new attack vector against business travelers and their corporate accounts.
IT researchers have discovered hotel WiFi routers that have been compromised by attackers. Through these manipulated routers, Russian attackers intercept the network traffic of hotel guests and capture Microsoft 365 login credentials.
The method specifically targets business travelers, whose authentication credentials are intercepted when establishing connections to corporate accounts. For organizations, this presents a significant risk: once attackers possess valid login credentials, they can access sensitive data, email archives, and collaboration tools without further obstacles.
This attack pattern underscores the need for organizations to train their employees on the use of public WiFi networks and enforce VPN connections, particularly for access to business-critical systems. Additionally, multi-factor authentication and conditional access policies should be enabled in Microsoft 365.
Source: www.heise.de · Published 27 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.