Back to Feed
Identity & AccessJul 27, 2026

Hackers Compromise Hotel Wi-Fi Gateways to Hijack Microsoft 365 Accounts

Hackers compromise hotel Wi-Fi gateways to redirect travelers to fake Microsoft 365 login pages and steal credentials.

Summary

A campaign active since at least June 2026 has compromised Wi-Fi gateways in multiple countries to redirect business travelers to fake Microsoft 365 login pages, stealing credentials and authorization tokens. Attackers gain administrative access to hotel and conference network equipment, manipulate DNS responses, and in some cases exploit Microsoft's device-code authentication to bypass MFA. The techniques resemble earlier APT28 operations, though ReliaQuest found no definitive attribution to the Russian group.

Full text

Security Phishing ScamHackers Compromise Hotel Wi-Fi Gateways to Hijack Microsoft 365 Accounts Compromised hotel Wi-Fi gateways redirect business travelers to fake Microsoft 365 login pages allowing attackers to steal credentials and authorization tokens. byWaqasJuly 27, 20263 minute read Listen to this article 0:00 — ← 10s ▶ Play 10s → Speed 0.75× 1× 1.25× 1.5× 2× Voice Loading voices… Press play to start listening Employees connecting to hotel or conference Wi-Fi are being targeted through the network equipment managing their connection, allowing attackers to redirect them to fake Microsoft login pages without sending a phishing email or infecting their computers. The campaign has operated since at least June 2026, according to research published by ReliaQuest, which identified compromised Wi-Fi gateways in several US cities, India, and Saudi Arabia, with connections involving employees from finance, legal, health care, energy, retail, and professional services organizations. For context, a hotel guest can join the venue’s genuine Wi-Fi network and still be exposed. Once attackers obtain administrative access to its gateway, they can alter the system that directs internet traffic for every connected guest. Compromised Wi-Fi Redirects Microsoft Logins When a device requests a website, DNS converts its name into the numerical address needed to reach it. A compromised gateway can provide a false answer, sending the browser to infrastructure operated by the attacker. ReliaQuest observed Microsoft-themed domains such as m365-owa.com, owa-ms365.com, ms365-device.com and ms365-live.com. These were not Microsoft services, but names designed to resemble legitimate Microsoft 365 and Outlook addresses. According to ReliaQuest’s blog post, travelers redirected to those pages could be asked to enter their login details. In a limited number of cases, the attackers also abused Microsoft’s device-code authentication process. A victim approving the request could give the attacker valid access tokens, even when multifactor authentication was completed on a genuine Microsoft page. The researchers believe the gateways may have been compromised through internet-facing management services combined with weak or reused administrator passwords. However, limited access to the affected devices prevented them from confirming the initial entry method. Some affected devices also attempted to use Windows Web Proxy Auto-Discovery, known as WPAD, to route application traffic through an attacker-controlled proxy. ReliaQuest saw this activity in roughly one-third of the examined cases but could not confirm that it succeeded. Attack flow (Via ReliaQuest) Techniques Resemble Earlier APT28 Campaigns ReliaQuest found similarities between this operation and earlier router attacks associated with APT28, also called Fancy Bear and Forest Blizzard. The Russian military intelligence group has previously been linked to DNS manipulation used to compromise Microsoft 365 accounts. Those similarities include taking control of network gateways, altering DNS responses and directing Microsoft authentication traffic through an adversary-in-the-middle service. ReliaQuest did not directly attribute the new campaign to APT28 because it found no shared infrastructure, reused code or other firm technical connection. Additionally, researchers found several differences. For instance, the current operation targets hotel and conference Wi-Fi equipment, while earlier APT28 reporting focused on home and small-office routers. Its domains and IP addresses also differ from infrastructure previously associated with the Russian group. Always-On VPN Stops the Wi-Fi Redirect ReliaQuest says an always-on, full-tunnel VPN can stop this attack by sending internet traffic and DNS requests through the company network. The hotel gateway cannot redirect the employee to a fake login page because the VPN handles those requests first. This protection needs to activate as soon as the device connects. A VPN that employees start manually may leave a short period when the hotel network can interfere with traffic, while split tunneling can leave DNS requests outside the protected connection. The researchers also warn that simply changing the device to Google’s 8.8.8.8 DNS service is not enough. Unless the request is encrypted, it still travels through the compromised gateway, which can intercept it and return a false address. Nevertheless, employees should reject unexpected Microsoft login or authorization requests on public Wi-Fi and tell their employer which venue and network they were using. Waqas I am a UK-based cybersecurity journalist with a passion for covering the latest happenings in cybersecurity and tech world. I am also into gaming, reading and investigative journalism. View Posts APT28Cyber AttackCybersecurityFancy BearForest BlizzardHotelsMicrosoftMicrosoft 365PhishingReliaQuestScamWIFI Leave a Reply Cancel reply View Comments (0) Related Posts Read More Cyber Attacks Cyber Events Security EU to Launch Bloc-wide Rapid Response Joint Cyber Unit The task force is quite similar to Washington’s ransomware task force, but the EU’s version will coordinate with authorities across the bloc. byDeeba Ahmed Read More Security EV Charging Stations at Risk of DoS Attacks Although a fix is available to patch vulnerabilities, the EV industry is slow in applying the updates. byDeeba Ahmed Read More Android Security Zerodium to pay up to $2.5 million for reporting 0-day Android exploits Zero-Day Android exploits are now more valuable then iOS exploits. byUzair Amir Read More News Android Malware Security BankBot banking malware found in flashlight and solitaire apps In a joint research, IT security researchers at Avast, ESET, and SfyLabs have discovered yet another malware on Google… byWaqas

Indicators of Compromise

  • domain — m365-owa.com
  • domain — owa-ms365.com
  • domain — ms365-device.com
  • domain — ms365-live.com

Entities

APT28 (threat_actor)Fancy Bear (threat_actor)Forest Blizzard (threat_actor)Microsoft (vendor)Microsoft 365 (product)ReliaQuest (vendor)