
Rogue Wi‑Fi Portals Steal Microsoft 365 Logins
ReliaQuest reports attackers are compromising public Wi‑Fi “captive portal” gateways (such as in hotels and conference centers) and changing their DNS settings…
Attackers are compromising hotel and conference center Wi‑Fi gateways and changing DNS settings so business travelers are silently redirected to fake Microsoft 365 login pages. When victims sign in, attackers steal passwords and potentially session tokens, allowing account takeover even when multi-factor authentication is enabled.
This campaign targets the network infrastructure that business travelers rely on rather than their inboxes. Attackers gain access to hotel or conference center Wi-Fi gateway and captive portal equipment, frequently through weak or default passwords. Once inside, they alter the gateway's DNS settings. When a guest connects to the public Wi-Fi and tries to reach Microsoft 365 services, the compromised gateway resolves the request to a malicious IP address instead of the legitimate one, routing the victim to a fraudulent phishing site built on a lookalike domain such as m365-owa[.]com.
The redirection happens at the network level rather than on the user's device, so traditional email security tools and some endpoint defenses may never see it. There is no phishing email to flag, no suspicious attachment, and no obvious link to inspect, because the malicious redirect is baked into the network path itself. Victims who enter their Microsoft 365 username and password on the fake page may also expose authenticated session tokens, which attackers can use to bypass multi-factor authentication through adversary-in-the-middle techniques. ReliaQuest assessed this tradecraft as similar to techniques previously linked to APT28 (Fancy Bear), reflecting a level of sophistication rated high.
The technique is broadly aimed at anyone who travels for work, but it carries particular weight for executives, finance, legal, healthcare staff, sales teams, and frequent travelers, along with IT and identity and access management personnel who manage corporate credentials. Affected industries extend beyond hospitality itself to banking, legal services, and healthcare, since employees from these sectors regularly connect to hotel and conference Wi-Fi while traveling.
Organizations should treat public Wi-Fi as untrusted by default and train travelers not to enter Microsoft 365 credentials if a sign-in page's domain looks unusual. Because this attack bypasses inbox-based controls entirely, awareness training should emphasize that credential theft can occur without any email involved. Mandating always-on, full-tunnel VPNs for staff devices helps ensure DNS queries and web traffic route through reliable corporate infrastructure rather than depending on potentially compromised public networks. Finally, users should understand that MFA alone is not a guarantee of safety if session tokens are captured, and should report suspicious sign-in prompts quickly.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Attackers compromise hotel or conference center Wi-Fi gateways, often through weak or default passwords, then change DNS settings so guests trying to reach Microsoft 365 are silently redirected to fraudulent phishing websites on lookalike domains such as m365-owa[.]com.
Yes. Stolen data may include authenticated session tokens, which attackers can use to bypass MFA through adversary-in-the-middle techniques.
The redirection happens at the network level rather than on the user's device, so traditional email security solutions and some endpoint defenses can miss it entirely.
Organizations can mandate always-on, full-tunnel VPNs so DNS queries and web traffic route through corporate infrastructure instead of relying on potentially compromised public Wi-Fi networks.
You’re in a hotel, hop on the Wi‑Fi, open Outlook, and a Microsoft 365 login pops up before anything loads. Behind the scenes, someone broke into the hotel’s Wi‑Fi gateway, changed DNS, and silently redirected you to a fake Microsoft 365 site on a lookalike domain like m365-owa.com. If you type your password there, they don’t just get your login, they can grab your authenticated session tokens and slip past MFA, with no phishing email in your inbox at all. When you’re on hotel or conference Wi‑Fi, pause, if the Microsoft 365 sign‑in page isn’t on the usual Microsoft or corporate domain, close it and use your VPN before trying again.

ReliaQuest reports attackers are compromising public Wi‑Fi “captive portal” gateways (such as in hotels and conference centers) and changing their DNS settings…

Researchers reported an ongoing campaign where attackers compromise hotel and conference venue Wi‑Fi routers and quietly redirect visitors’ web traffic through…

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…

Russian-linked threat actors sent generic-looking informational emails that required no clicking, but simply opening them in vulnerable Outlook Web Access…

Amazon says North Korea-linked actors compromised widely used npm packages (including debug and chalk) by tricking a trusted maintainer into signing in through…

The article describes real-world ways attackers get around multifactor authentication (MFA), including “push bombing” (MFA fatigue), phishing pages that relay…