Public Wi‑Fi DNS Hijacks Steal Microsoft 365 Logins

Schneier on Security · Medium sophistication
Last updated August 17, 2026

Attackers are compromising public Wi‑Fi equipment (such as in hotels and conference centers) and changing DNS settings so victims are silently redirected to look‑alike login pages. The goal is to capture usernames and passwords, including Microsoft 365 credentials, when users try to sign in.

Key findings

  • Attackers compromise public Wi‑Fi devices (hotels, conference centers, etc.) and modify DNS settings.
  • Victims are redirected to fake login pages without realizing it.
  • The intent is to steal credentials, including Microsoft 365 account logins.

Who’s being targeted

  • Commonly targeted roles: All employees, Frequent travelers, Executives, Sales and field teams, IT/security helpdesk (for response triage).
  • Affected industries: Hospitality (hotels), Conference and event venues, Any organization with traveling staff using public Wi‑Fi.
  • Attack channels: website.
  • Impersonated: Microsoft 365 sign-in page.

Awareness takeaways

  • Treat unexpected sign-in pages on public Wi‑Fi as suspicious; don’t enter work credentials unless you manually navigate to the known, official site/app.
  • Be extra cautious using hotel/conference Wi‑Fi for corporate logins; prefer a trusted hotspot or VPN when possible.
  • If you think you entered credentials into a suspicious page, change your password immediately and report it to IT/security.

Red flags to watch for

  • Login page appears unexpectedly after joining public Wi‑Fi
  • Slightly unusual URL/domain or certificate warnings
  • Sign-in prompt repeats even after entering correct credentials
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You connect to hotel Wi‑Fi, open your browser, and boom, “Microsoft 365 Sign in” pops up before anything else loads. Behind the scenes, hacked public Wi‑Fi gear has its DNS changed, silently sending you to a look‑alike Microsoft 365 page built only to steal your username and password. Red flags: the sign‑in page appears right after joining Wi‑Fi, the URL looks a bit off or throws a certificate warning, or it keeps asking you to sign in again even after you type the right password. If a Microsoft 365 login appears on public Wi‑Fi, don’t trust the pop‑up, close it and open the official Microsoft 365 site or app yourself before you sign in.

Categories

Similar attacks

Hotel Wi‑Fi Lures and Entra Vishing Hit Users

Hotel Wi‑Fi Lures and Entra Vishing Hit Users

The article reports real-world social engineering operations, including a hotel Wi‑Fi campaign that pushed fake updates and device-code phishing to steal Microsoft 365 access. It also describes an alleged Microsoft Entra vishing campaign tied to data theft claims at Brinks Home, reinforcing the…

August 7, 2026
Hotel WiFi Scam Pushes Fake Updates and Malware

Hotel WiFi Scam Pushes Fake Updates and Malware

A Russia-linked threat group compromised hotel WiFi captive portals to redirect guests to fake “verification” pages. Victims were pushed toward either copying commands into a terminal to install malware or entering Microsoft credentials on spoofed login pages that added an attacker-controlled…

August 7, 2026
Russian Hackers Hijack Hotel Wi‑Fi Login Pages

Russian Hackers Hijack Hotel Wi‑Fi Login Pages

Microsoft says a Russia-linked group compromised hotel and venue Wi‑Fi captive portals to show convincing fake prompts during the normal “connect to Wi‑Fi” flow. The prompts try to trick travelers into installing malware, running commands, or approving a Microsoft sign-in that grants the attacker…

August 4, 2026
Hackers Hijack Hotel Wi‑Fi to Steal M365 Logins

Hackers Hijack Hotel Wi‑Fi to Steal M365 Logins

Microsoft reports a Russian state-backed operation that compromises hotel and conference Wi‑Fi “captive portals” to redirect travelers to fake Microsoft 365 sign-in pages or fake update prompts that install malware. One method abuses Microsoft’s device-code login flow so victims unknowingly approve…

August 4, 2026
Hijacked Hotel Wi‑Fi Tricks Travelers Into Logins

Hijacked Hotel Wi‑Fi Tricks Travelers Into Logins

Microsoft says a Russian-linked group is abusing hotel and conference Wi‑Fi “captive portals” to trick travelers into entering corporate credentials or installing malware. Victims see what looks like a normal Wi‑Fi login flow, but attackers manipulate DNS/website traffic to redirect them to fake…

August 4, 2026
Midnight Blizzard Hijacks Hotel Wi‑Fi to Phish Guests

Midnight Blizzard Hijacks Hotel Wi‑Fi to Phish Guests

Microsoft says a Russia-linked group compromised hotel and conference guest Wi‑Fi sign-in systems to redirect travelers to phishing pages and fake “update” prompts. The goal was to steal credentials (including Microsoft 365) and push malware when devices automatically check connectivity after…

August 4, 2026