Open account

Hotel Wi-Fi phishing attack targets Microsoft logins

The article describes a cybersecurity campaign in which hackers compromise hotel and conference center Wi‑Fi gateways to redirect business travelers to fake Microsoft 365 login pages. Researchers at ReliaQuest say the activity has been active since at least June and has affected gateways in several U.S. cities, with organizations across financial services, legal, health care, energy, retail and professional services potentially exposed. Attackers may steal credentials or use device-code prompts to bypass MFA, and in some cases try WPAD abuse to route traffic through malicious proxies. The market-relevant takeaway is heightened operational risk for enterprises, especially firms with traveling employees, because compromised accounts can lead to payment fraud, internal phishing and broader security incidents. The article also emphasizes that public DNS alone may not stop the attack and recommends always-on VPNs, hotspots, updated devices and stricter Microsoft Entra ID settings.

Category

Microsoft

Sentiment

Bearish

Event

Security incident

Reading time

1 min