Hotel Wi-Fi DNS hijacking Microsoft 365 phishing campaign
Campaign
Updated: 24.07.2026 20:50
· First: 24.07.2026 20:50
· 📰 1 src / 1 articles
· H score: 34
Compromised Wi-Fi gateways at hotels and conference centers are redirecting travelers to fake Microsoft 365 login pages, creating a live credential-theft campaign that can expose business email, documents, and other sensitive data. The operation has been active since at least June and has reached organizations across financial services, professional services, legal, health care, energy, and retail in the U.S. and abroad. Attackers are using DNS changes, device-code authentication tricks, and in some cases WPAD abuse to push victims onto attacker-controlled login pages and bypass MFA.