[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$ffHovE5--vIDcxhhcVMjK_X4gQrfR1VNrsEF_jTJbVzw":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":27,"created_at":28,"published_at":29,"article":30,"tags":34,"podcasts":53},"50b0dc88-656e-4b90-b953-d478b49d8615","hotel-wi-fi-gateways-weaponized-to-steal-microsoft-365-credentials","4f7cd7ee-c295-433e-b8db-066938d01150","Hotel Wi-Fi Gateways Weaponized to Steal Microsoft 365 Credentials","Attackers compromised poorly secured hotel and conference Wi-Fi gateway devices to manipulate DNS and redirect business travelers to convincing fake Microsoft 365 login pages, harvesting credentials and session tokens. The exploitation of Microsoft's device-code authentication flow allowed attackers to bypass MFA entirely, demonstrating that MFA alone is not a silver bullet when authentication protocols themselves can be abused. This attack is particularly dangerous because victims have no visible warning signs — they believe they are on a legitimate network using a trusted service. Business travelers are high-value targets as they routinely access sensitive corporate resources on unfamiliar networks, making robust endpoint and authentication controls critical.","**Immediate actions:**\n- Enforce phishing-resistant MFA (FIDO2\u002Fhardware keys) for all Microsoft 365 accounts to prevent device-code authentication abuse.\n- Instruct employees to use a corporate VPN before accessing any company resources on hotel or public Wi-Fi networks.\n- Disable or restrict the OAuth device-code authentication flow in Azure AD\u002FEntra ID conditional access policies unless explicitly required.\n\n**Long-term improvements:**\n- Implement Zero Trust Network Access (ZTNA) so corporate resources are never directly exposed to untrusted network paths.\n- Conduct regular security awareness training specifically covering risks of public Wi-Fi, fake login portals, and social engineering targeting travelers.\n- Audit and harden all network gateway equipment (default credentials, firmware versions, admin access) used in corporate-managed facilities.\n\n**Detection measures:**\n- Deploy anomalous sign-in detection and alert on impossible travel, unfamiliar device, or token reuse events in Microsoft Entra ID \u002F Defender for Identity.\n- Monitor DNS query logs for unexpected redirections or anomalous external DNS resolver usage on managed networks.\n- Establish a threat intelligence feed for known APT TTPs (e.g., APT28 device-code phishing) and apply corresponding detection rules in your SIEM.",[12,13,14,15,16,17,18,19,20,21,22,23,24,25,26],"CIS Control 4 – Secure Configuration of Enterprise Assets","CIS Control 6 – Access Control Management","CIS Control 9 – Email and Web Browser Protections","CIS Control 14 – Security Awareness and Skills Training","NIST SP 800-63B – Digital Identity Guidelines (Phishing-Resistant AAL3)","NIST AC-17 – Remote Access","NIST AC-2 – Account Management","NIST SI-3 – Malicious Code Protection","NIST SC-20\u002FSC-21 – DNS Security","MITRE ATT&CK T1557 – Adversary-in-the-Middle","MITRE ATT&CK T1528 – Steal Application Access Token","MITRE ATT&CK T1566.003 – Phishing: Spearphishing via Service","GDPR Article 32 – Security of Processing (for EU traveler data at risk)","ISO\u002FIEC 27001 A.9.4 – System and Application Access Control","ITIL Service Transition – Change and Configuration Management","published","2026-07-27T16:21:48.731215+00:00","2026-07-27T16:21:48.626+00:00",{"id":7,"url":31,"slug":32,"title":33},"https:\u002F\u002Fhackread.com\u002Fhackers-hotel-wi-fi-gateways-hijack-microsoft-365-accounts\u002F","hackers-compromise-hotel-wi-fi-gateways-to-hijack-microsoft-365-accounts-567217","Hackers Compromise Hotel Wi-Fi Gateways to Hijack Microsoft 365 Accounts",[35,41,47],{"id":36,"name":37,"slug":38,"description":39,"color":40},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":42,"name":43,"slug":44,"description":45,"color":46},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":48,"name":49,"slug":50,"description":51,"color":52},"f43a7f30-5046-4b10-9dba-1a704139821e","Network Segmentation","network-segmentation","Lateral movement, flat networks, missing firewalls","#06b6d4",[]]