highPhishing

Hotel Wi-Fi DNS Hijacking Campaign Targeting Microsoft 365 Credentials

First seen Jul 25, 2026 · Updated Jul 25, 2026

DNS hijackingcredential theftMicrosoft 365phishinghospitalitytravel-securitycaptive-portal-abuseagent-relevant

Threat actors are compromising DNS settings on hotel and conference center Wi-Fi routers/gateways to silently redirect guests to convincing fake Microsoft 365 login pages. Victims who enter credentials on these spoofed portals have their Microsoft 365 accounts stolen, potentially exposing corporate email, files, and connected services. The campaign leverages trust in hotel network infrastructure and captive portal flows to bypass user suspicion.

Technical Analysis

Attackers gain access to hotel/conference Wi-Fi infrastructure—likely via default or weak admin credentials, unpatched router firmware, or exposed management interfaces—and modify DNS resolver settings to intercept and redirect traffic. When guests connect and attempt to reach legitimate services or the captive portal, requests are redirected to attacker-controlled phishing pages that closely mimic Microsoft 365 login flows, harvesting usernames, passwords, and potentially MFA tokens via adversary-in-the-middle (AiTM) proxy techniques. No specific CVE has been disclosed for the router/gateway compromise vector, suggesting reliance on weak credentials or known unpatched firmware bugs rather than a novel zero-day. Because business travelers frequently connect corporate laptops running AI coding assistants, RAG clients, or agent orchestration tools to hotel Wi-Fi, stolen Microsoft 365 credentials and session tokens could grant attackers access to connected Graph API integrations, SharePoint/OneDrive data sources, and Azure AD-linked service accounts that AI agents rely on for authentication and data retrieval, enabling downstream supply-chain or data-exfiltration attacks against agent pipelines.

Affected Systems

Hotel and conference center Wi-Fi routers/access points with modifiable DNS settings; guest devices connecting to compromised networks; Microsoft 365 accounts of affected users; any enterprise SSO/Azure AD integrations tied to compromised credentials

Indicators of Compromise

  • Fake Microsoft 365 login pages (domains not fully disclosed in source)
  • Modified DNS resolver entries on hotel Wi-Fi gateways
  • Captive portal redirect anomalies

Remediation Steps

  1. 1

    Use VPN on public Wi-Fi

    Always connect through a trusted corporate VPN when using hotel or conference Wi-Fi to prevent DNS-level interception and redirection.

  2. 2

    Enable phishing-resistant MFA

    Deploy FIDO2/WebAuthn hardware security keys for Microsoft 365 accounts to prevent credential and session token theft via AiTM phishing pages.

  3. 3

    Verify URLs before login

    Train users to manually verify the URL and TLS certificate of any Microsoft 365 login page before entering credentials, especially on unfamiliar networks.

  4. 4

    Monitor for anomalous sign-ins

    Use Azure AD/Entra ID risk detection and conditional access policies to flag and block logins from unfamiliar IPs or impossible travel patterns.

  5. 5

    Audit and harden hotel/venue network infrastructure

    For hospitality operators, change default router credentials, patch firmware, disable remote DNS management, and monitor for unauthorized configuration changes.

  6. 6

    Rotate exposed credentials

    Immediately reset passwords and revoke active sessions for any accounts suspected of being phished, and audit connected apps/API keys used by AI agents or automation tools.

Industries Most Exposed

hospitalitytravelcorporate enterprisetechnologyfinance

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.