Cybersecurity firm ReliaQuest has identified a campaign where hackers are altering DNS settings on Wi-Fi devices located in hotels and conference centers. This manipulation redirects users attempting to access Microsoft 365 services to fraudulent login pages controlled by the attackers. The campaign has been active since at least June and has been observed in multiple U.S. cities and international regions like India and Saudi Arabia.
The compromised Wi-Fi gateways serve corporate events, making the campaign a threat to various industries. Organizations in financial services, professional services, legal, healthcare, energy, and retail have been affected. By hijacking Microsoft 365 accounts, attackers could gain access to sensitive business information, communications, and private documents, indicating a broad, non-sector-specific targeting strategy aimed at traveling employees.
The initial access method to the Wi-Fi appliances is currently unknown, but ReliaQuest suggests attackers may exploit weakly protected management interfaces or vulnerabilities. Once administrative access is gained, the threat actor modifies the gateway's DNS settings to redirect legitimate domain requests to attacker-controlled infrastructure. ReliaQuest identified four domains used for these fake Microsoft login portals: m365-owa[.]com, owa-ms365[.]com, ms365-device[.]com, and ms365-live[.]com.
When DNS settings are altered, users are directed to phishing pages where they might enter their Microsoft 365 credentials. In some instances, a device-code authentication flow is observed, where targets are prompted on a fake Microsoft page. Approving this prompt authorizes a session initiated by the attacker, leading to a legitimate OAuth token being issued to the attacker's client, effectively bypassing multi-factor authentication (MFA) without directly stealing credentials.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Hackers are redirecting users to fake Microsoft 365 login pages by changing DNS settings on Wi-Fi devices in hotels and conference centers. This campaign, ongoing since June, affects organizations across various sectors by potentially compromising sensitive business information.