Skip to content

Attackers Compromise Hotel Wi-Fi Gateways to Hijack Microsoft 365 Accounts

In brief: Attackers can steal Microsoft 365 accounts from guests through DNS poisoning on compromised Wi-Fi gateways without touching their devices or the corporate network.

Since at least June, threat actors have been manipulating captive portal gateways and portal appliances in hotels and conference centers to compromise Microsoft 365 accounts of traveling employees. The attackers redirect network traffic and steal login credentials without infecting the endpoint devices themselves.

The threat research team at ReliaQuest has documented a campaign in which attackers first take over admin access to Wi-Fi gateways and portal appliances in hotels, conference centers, and similar public facilities. This typically occurs through weak or reused admin credentials combined with exposed interfaces such as SSH (Secure Shell), SNMP (Simple Network Management Protocol), or web consoles.

After obtaining admin access, the attackers inject false DNS data to redirect regular network traffic to fraudulent domains. In the campaign tracked by ReliaQuest, four attacker domains—m365-owa[.]com, owa-ms365[.]com, ms365-device[.]com, and ms365-live[.]com—were used as Microsoft impersonations. This technique works because devices trust DNS queries by default: the gateway, which sits at the network perimeter, can intercept and manipulate DNS requests before they even leave the endpoint, without the procedure being visible at the endpoint level. Affected users are from companies in the financial and insurance sector, legal profession, retail, healthcare, and energy sector; the attacks occurred in several U.S. cities as well as in India and Saudi Arabia.

For security practitioners, this is problematic because compromising a single account can lead to significant data loss—a successful account can, for example, access SharePoint data and email archives. For network operators, there is also considerable reputational risk, as user compromises damage trust and brand perception.

ReliaQuest warns that common protective measures are often insufficient: configuring “secure” DNS providers such as Google (8.8.8.8) or Cloudflare (1.1.1.1) changes the intended target, but not the path to it—the gateway still controls the network path and can intercept queries. DNSSEC (Domain Name System Security Extensions) with digital signatures and public-key cryptography offers only partial mitigation, as even signed DNS responses remain vulnerable to gateway manipulation.


Source: www.csoonline.com · Published July 28, 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: