
Hotel Wi‑Fi Hijacks Microsoft 365 Logins
Researchers report attackers compromising hotel and conference Wi‑Fi gateway equipment to silently redirect travelers to fake Microsoft 365 sign-in pages,…
Researchers report attackers compromising hotel and venue Wi‑Fi “captive portal” gateways to redirect Microsoft 365 sign-ins to attacker-controlled lookalike domains. Victims can have their Microsoft 365 credentials stolen without clicking a phishing link or installing malware, because the manipulation happens at the network gateway level.
Researchers at ReliaQuest identified a campaign in which attackers compromised captive Wi-Fi gateway and portal appliances at hotels, conference centers, and similar shared venues. Once a gateway is compromised, an attacker can use DNS poisoning to silently redirect a connected user's Microsoft 365 sign-in traffic to attacker-controlled lookalike domains. Four Microsoft-impersonation domains were identified in this campaign: m365-owa[.]com, owa-ms365[.]com, ms365-device[.]com, and ms365-live[.]com. Because the manipulation happens at the network level, victims can have their Microsoft 365 credentials stolen without clicking a phishing link or installing malware on their device.
This technique bypasses the usual mental checklist people use to spot phishing. There is no suspicious email, no attachment, and no unusual download. The user simply connects to a hotel or conference network as normal and is presented with what looks like a standard Microsoft 365 login prompt. The compromised gateways were found across multiple US cities as well as in India and Saudi Arabia, and affected users across professional services, financial services, legal, retail, healthcare, and energy. Many organizations also assume that pointing devices at a specific DNS provider protects them, but the local network gateway can still intercept and redirect DNS traffic before it ever reaches that provider.
Because endpoint telemetry typically confirms a redirect only after it has already occurred, prevention-focused controls matter more than detection alone. Recommended steps include:
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Attackers compromise captive Wi-Fi gateway or portal appliances at hotels and conference centers, then use DNS poisoning to silently redirect users' Microsoft 365 sign-in traffic to attacker-controlled lookalike domains.
No. Because the redirection happens at the network gateway level, victims can have their Microsoft 365 credentials stolen without clicking a link or installing malware.
No. Locking devices to a specific DNS provider does not help because the local network gateway can still intercept or redirect DNS queries before they reach that provider.
Security researchers recommend requiring a full-tunnel VPN that routes all traffic, including DNS, through an encrypted connection to a trusted VPN server.
You connect to hotel Wi‑Fi, open Outlook, and the Microsoft 365 login pops up like normal… but the hotel’s Wi‑Fi is quietly in the middle. Researchers found hotel and conference Wi‑Fi gateways doing DNS hijacks, silently redirecting Microsoft 365 logins to lookalike sites like m365-owa.com or owa-ms365.com, even if you set DNS to 8.8.8.8 or 1.1.1.1. Here’s the trap: you’re on public Wi‑Fi, Outlook suddenly wants you to sign in again, the page looks perfect, but the URL is ms365-live.com instead of login.microsoftonline.com, and the certificate details don’t match Microsoft. On hotel or conference Wi‑Fi, before typing your Microsoft 365 password, pause and check one thing: the address bar must say login.microsoftonline.com, if it doesn’t, stop and connect through your full‑tunnel VPN first.

Researchers report attackers compromising hotel and conference Wi‑Fi gateway equipment to silently redirect travelers to fake Microsoft 365 sign-in pages,…

Researchers reported an ongoing campaign where attackers compromise hotel and conference venue Wi‑Fi routers and quietly redirect visitors’ web traffic through…

Attackers are taking over hotel and conference Wi‑Fi gateways and changing DNS settings so travelers are silently redirected to fake Microsoft 365 sign-in…

A voicemail-themed phishing campaign (“Kali365 Ringer”) targeted financial and insurance organizations using a missed-call notification and a Google Sites page…

Researchers demonstrated a new “agent data injection” technique where attackers plant content (like a review or GitHub comment) that an AI agent mistakenly…

Microsoft reports attackers linked to ShinyHunters spent a year getting into corporate Salesforce data without exploiting Salesforce bugs. One key method was…