Hotel Wi-Fi DNS Hijacking Campaign Targeting Microsoft 365 Credentials
First seen Jul 25, 2026 · Updated Jul 25, 2026
Threat actors are compromising DNS settings on hotel and conference center Wi-Fi routers/gateways to silently redirect guests to convincing fake Microsoft 365 login pages. Victims who enter credentials on these spoofed portals have their Microsoft 365 accounts stolen, potentially exposing corporate email, files, and connected services. The campaign leverages trust in hotel network infrastructure and captive portal flows to bypass user suspicion.
Technical Analysis
Attackers gain access to hotel/conference Wi-Fi infrastructure—likely via default or weak admin credentials, unpatched router firmware, or exposed management interfaces—and modify DNS resolver settings to intercept and redirect traffic. When guests connect and attempt to reach legitimate services or the captive portal, requests are redirected to attacker-controlled phishing pages that closely mimic Microsoft 365 login flows, harvesting usernames, passwords, and potentially MFA tokens via adversary-in-the-middle (AiTM) proxy techniques. No specific CVE has been disclosed for the router/gateway compromise vector, suggesting reliance on weak credentials or known unpatched firmware bugs rather than a novel zero-day. Because business travelers frequently connect corporate laptops running AI coding assistants, RAG clients, or agent orchestration tools to hotel Wi-Fi, stolen Microsoft 365 credentials and session tokens could grant attackers access to connected Graph API integrations, SharePoint/OneDrive data sources, and Azure AD-linked service accounts that AI agents rely on for authentication and data retrieval, enabling downstream supply-chain or data-exfiltration attacks against agent pipelines.
Affected Systems
Hotel and conference center Wi-Fi routers/access points with modifiable DNS settings; guest devices connecting to compromised networks; Microsoft 365 accounts of affected users; any enterprise SSO/Azure AD integrations tied to compromised credentials
Indicators of Compromise
- Fake Microsoft 365 login pages (domains not fully disclosed in source)
- Modified DNS resolver entries on hotel Wi-Fi gateways
- Captive portal redirect anomalies
Remediation Steps
- 1
Use VPN on public Wi-Fi
Always connect through a trusted corporate VPN when using hotel or conference Wi-Fi to prevent DNS-level interception and redirection.
- 2
Enable phishing-resistant MFA
Deploy FIDO2/WebAuthn hardware security keys for Microsoft 365 accounts to prevent credential and session token theft via AiTM phishing pages.
- 3
Verify URLs before login
Train users to manually verify the URL and TLS certificate of any Microsoft 365 login page before entering credentials, especially on unfamiliar networks.
- 4
Monitor for anomalous sign-ins
Use Azure AD/Entra ID risk detection and conditional access policies to flag and block logins from unfamiliar IPs or impossible travel patterns.
- 5
Audit and harden hotel/venue network infrastructure
For hospitality operators, change default router credentials, patch firmware, disable remote DNS management, and monitor for unauthorized configuration changes.
- 6
Rotate exposed credentials
Immediately reset passwords and revoke active sessions for any accounts suspected of being phished, and audit connected apps/API keys used by AI agents or automation tools.
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.