← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Hackers modify DNS settings on hotel/conference Wi-Fi.
  • Users are redirected to fake Microsoft 365 login pages.
  • Campaign impacts financial, legal, healthcare, energy, and retail sectors.
  • Attackers can bypass MFA using device-code authentication flow.

Wi-Fi DNS Hijacking Campaign

Cybersecurity firm ReliaQuest has identified a campaign where hackers are altering DNS settings on Wi-Fi devices located in hotels and conference centers. This manipulation redirects users attempting to access Microsoft 365 services to fraudulent login pages controlled by the attackers. The campaign has been active since at least June and has been observed in multiple U.S. cities and international regions like India and Saudi Arabia.

Impact on Organizations

The compromised Wi-Fi gateways serve corporate events, making the campaign a threat to various industries. Organizations in financial services, professional services, legal, healthcare, energy, and retail have been affected. By hijacking Microsoft 365 accounts, attackers could gain access to sensitive business information, communications, and private documents, indicating a broad, non-sector-specific targeting strategy aimed at traveling employees.

Attack Methodology

The initial access method to the Wi-Fi appliances is currently unknown, but ReliaQuest suggests attackers may exploit weakly protected management interfaces or vulnerabilities. Once administrative access is gained, the threat actor modifies the gateway's DNS settings to redirect legitimate domain requests to attacker-controlled infrastructure. ReliaQuest identified four domains used for these fake Microsoft login portals: m365-owa[.]com, owa-ms365[.]com, ms365-device[.]com, and ms365-live[.]com.

MFA Bypass and Credential Theft

When DNS settings are altered, users are directed to phishing pages where they might enter their Microsoft 365 credentials. In some instances, a device-code authentication flow is observed, where targets are prompted on a fake Microsoft page. Approving this prompt authorizes a session initiated by the attacker, leading to a legitimate OAuth token being issued to the attacker's client, effectively bypassing multi-factor authentication (MFA) without directly stealing credentials.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~15 min · 15 stories · Jul 24

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Hackers are redirecting users to fake Microsoft 365 login pages by changing DNS settings on Wi-Fi devices in hotels and conference centers. This campaign, ongoing since June, affects organizations across various sectors by potentially compromising sensitive business information.