Hackers have compromised Wi-Fi systems in hotels and conference centers, creating fake Microsoft 365 login pages. Business travelers face high risks, as they may unknowingly provide login information to these fake sites.
Wi-Fi Phishing Campaign
ReliaQuest, a cybersecurity firm, discovered this campaign active since at least June. Compromised Wi-Fi gateways have been identified across several U.S. cities. Affected sectors include financial and professional services, legal, healthcare, energy, and retail, suggesting a focus on traveling employees.
How the Attack Works
By gaining access to Wi-Fi gateways, hackers change DNS settings. This redirect leads users to fake Microsoft login pages. The process is often seamless, making detection difficult until information is inputted on a fraudulent page.
Potential Gateways to Access
Access may occur through weak passwords, vulnerable entry points, or delayed software updates. These methods allow attackers to alter DNS configurations, posing risks without directly interacting with user devices.
Fake Login Pages and Fraud Potential
The attackers have registered domains mimicking Microsoft. Victims might overlook suspicious URLs during busy schedules. Fake pages collect Microsoft 365 credentials, which can lead to unauthorized business email access and more severe fraud.
Device Code Prompt Manipulation
Hackers can bypass multi-factor authentication using deceptive device codes. Users, trusting the legitimacy of the prompt, might inadvertently grant access, mistaking it for a legitimate sign-in process.
WPAD Exploitation Attempts
Web Proxy Auto-Discovery (WPAD) was targeted in about one-third of the cases. Though success is uncertain, such actions indicate an interest in monitoring network activities beyond login credentials.
Security Measures
Using a public DNS alone might not be effective. ReliaQuest reports that compromised gateways can manipulate responses before reaching intended public resolvers. However, encrypted DNS provides better protection. A strict configuration prevents falling back to unencrypted connections.
Protective Steps While Traveling
- Use a full-tunnel VPN to safeguard internet traffic.
- Consider using a phone’s hotspot to bypass hotel gateways.
- Carefully verify Microsoft login URLs.
- Do not approve unfamiliar device code requests without verifying.
- Regularly update devices and browser software for security patches.
- Employ strong antivirus software to detect potential threats.
- Request corporate review of Microsoft Entra ID settings for additional security.
Conclusion
The phishing campaign demonstrates that hotel Wi-Fi networks can look harmless, yet mislead users to fake Microsoft 365 login pages. Slow down when prompted to enter sensitive information, and leverage VPNs or mobile hotspots for secure connections.
For further security tips and insights, visit CyberGuy.com.

Impact of Extreme Heat on Flight Operations
Beware Fake Party Invitations: Tips to Protect Your Computer
Compensation Available in Labcorp Data Breach Settlement
Transforming Healthcare with AI: A Human-Centric Approach
White House to Exempt Some AI Systems from Government Vetting
SpaceX Reports Significant Loss After Initial Public Offering