Microsoft: Hackers Hijack Hotel Wi-Fi Gateways to Steal Microsoft 365 Accounts Without Phishing

Microsoft: Hackers Hijack Hotel Wi-Fi Gateways to Steal Microsoft 365 Accounts Without Phishing

Hotel Wi-Fi Gateways Hijacked to Steal Microsoft 365 Accounts in Global Campaign

Threat actors are targeting hotel and conference-center Wi-Fi gateways to compromise Microsoft 365 accounts from traveling employees, bypassing traditional phishing or endpoint infections. The campaign, active since at least June 2026, exploits DNS poisoning and, in some cases, Microsoft’s device-code flow to redirect users to attacker-controlled infrastructure.

The attacks have been observed in shared Wi-Fi environments across multiple U.S. cities, India, and Saudi Arabia, impacting organizations in financial services, legal, healthcare, energy, retail, and professional services. Rather than focusing on a single industry, the campaign appears to target travelers using vulnerable captive-portal appliances common in hotels, conference centers, airports, and coworking spaces.

Once attackers gain administrative access to these gateways likely through exposed management services or weak credentials they alter DNS settings to redirect users attempting to log into Microsoft 365. By poisoning DNS responses, the attackers substitute legitimate Microsoft sign-in domains with spoofed pages hosted on malicious infrastructure. Domains linked to the operation include m365-owa[.]com, owa-ms365[.]com, ms365-device[.]com, and ms365-live[.]com, associated with IP addresses 31.57.243[.]154, 104.194.159[.]150, and the DNS-poisoning response address 38.146.28[.]75.

The attack is particularly stealthy, as it requires no phishing emails, malicious attachments, or endpoint exploits. A single compromised gateway can expose all connected devices that accept its DHCP configuration. While the tactics resemble those of APT28 (also known as Fancy Bear or Forest Blizzard) including adversary-in-the-middle techniques and credential theft there is no direct technical evidence attributing this campaign to the group.

In some cases, attackers also attempted to abuse the Web Proxy Auto-Discovery Protocol (WPAD) on Windows and macOS systems, directing devices to malicious proxy auto-configuration files to intercept application traffic. The incident underscores the risks of unsecured public Wi-Fi networks and the need for robust network-level defenses.

Source: https://cyberpress.org/hotel-wi-fi-hijacks-microsoft-365-accounts/

Microsoft TPRM report: https://www.rankiteo.com/company/microsoft-security

"id": "mic1784881741",
"linkid": "microsoft-security",
"type": "Cyber Attack",
"date": "7/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Traveling employees using '
                                              'shared Wi-Fi',
                        'industry': ['Financial Services',
                                     'Legal',
                                     'Healthcare',
                                     'Energy',
                                     'Retail',
                                     'Professional Services'],
                        'location': ['U.S. cities', 'India', 'Saudi Arabia'],
                        'type': 'Organizations'},
                       {'industry': 'Hospitality, Travel, Shared Workspaces',
                        'location': ['U.S. cities', 'India', 'Saudi Arabia'],
                        'type': 'Hotels, Conference Centers, Airports, '
                                'Coworking Spaces'}],
 'attack_vector': ['DNS Poisoning',
                   'Adversary-in-the-Middle (AitM)',
                   'WPAD Abuse'],
 'data_breach': {'personally_identifiable_information': 'Potential (depends on '
                                                        'account contents)',
                 'sensitivity_of_data': 'High (corporate emails, documents, '
                                        'PII)',
                 'type_of_data_compromised': 'Microsoft 365 account '
                                             'credentials'},
 'date_detected': '2026-06-01',
 'description': 'Threat actors are targeting hotel and conference-center Wi-Fi '
                'gateways to compromise Microsoft 365 accounts from traveling '
                'employees, bypassing traditional phishing or endpoint '
                'infections. The campaign exploits DNS poisoning and, in some '
                'cases, Microsoft’s device-code flow to redirect users to '
                'attacker-controlled infrastructure. The attacks have been '
                'observed in shared Wi-Fi environments across multiple U.S. '
                'cities, India, and Saudi Arabia, impacting organizations in '
                'financial services, legal, healthcare, energy, retail, and '
                'professional services. Attackers gain administrative access '
                'to gateways, alter DNS settings, and redirect users to '
                'spoofed Microsoft sign-in pages. The campaign is stealthy, '
                'requiring no phishing emails or endpoint exploits, and has '
                'been linked to domains such as m365-owa[.]com, '
                'owa-ms365[.]com, and IP addresses like 31.57.243[.]154. In '
                'some cases, attackers abused WPAD to intercept application '
                'traffic.',
 'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
                                       'compromised accounts',
            'data_compromised': 'Microsoft 365 account credentials',
            'identity_theft_risk': 'High (PII and corporate data exposure)',
            'operational_impact': 'Unauthorized access to corporate accounts '
                                  'and data',
            'systems_affected': ['Wi-Fi gateways',
                                 'Connected devices accepting DHCP '
                                 'configurations']},
 'initial_access_broker': {'entry_point': 'Compromised Wi-Fi gateways',
                           'high_value_targets': 'Traveling employees with '
                                                 'corporate Microsoft 365 '
                                                 'accounts'},
 'investigation_status': 'Ongoing',
 'lessons_learned': 'Unsecured public Wi-Fi networks pose significant risks; '
                    'robust network-level defenses (e.g., DNS security, WPAD '
                    'hardening) are critical to prevent credential theft.',
 'motivation': 'Credential theft for unauthorized access',
 'post_incident_analysis': {'corrective_actions': ['Hardening gateway security',
                                                   'Implementing DNSSEC',
                                                   'Disabling WPAD or securing '
                                                   'PAC files',
                                                   'Enforcing VPN usage on '
                                                   'public networks'],
                            'root_causes': ['Exposed management services on '
                                            'Wi-Fi gateways',
                                            'Weak credentials',
                                            'Lack of DNS security',
                                            'Unsecured WPAD configurations']},
 'recommendations': ['Secure Wi-Fi gateway management interfaces with strong '
                     'credentials and MFA',
                     'Monitor and harden DNS configurations to prevent '
                     'poisoning',
                     'Disable or secure WPAD on corporate devices',
                     'Educate employees on risks of public Wi-Fi and use of '
                     'VPNs',
                     'Implement network segmentation and enhanced monitoring '
                     'for shared networks'],
 'references': [{'source': 'Cybersecurity Report'}],
 'threat_actor': 'APT28 (Fancy Bear/Forest Blizzard) - suspected but not '
                 'confirmed',
 'title': 'Hotel Wi-Fi Gateways Hijacked to Steal Microsoft 365 Accounts in '
          'Global Campaign',
 'type': 'Credential Theft',
 'vulnerability_exploited': ['Exposed management services',
                             'Weak credentials',
                             'Unsecured public Wi-Fi networks']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.