Find notable cyber news and cases, enriched with sources, timelines, and signals.

Hotel Wi-Fi DNS hijacking Microsoft 365 phishing campaign

Campaign
First reported
Last updated
Happening score
H score 34
1 unique sources, 1 articles

Summary

Hide ▲

Compromised Wi-Fi gateways at hotels and conference centers are redirecting travelers to fake Microsoft 365 login pages, creating a live credential-theft campaign that can expose business email, documents, and other sensitive data. The operation has been active since at least June and has reached organizations across financial services, professional services, legal, health care, energy, and retail in the U.S. and abroad. Attackers are using DNS changes, device-code authentication tricks, and in some cases WPAD abuse to push victims onto attacker-controlled login pages and bypass MFA.

Related Happenings

DNS poisoning campaign targeting captive Wi‑Fi routers to harvest corporate credentials

Campaign
H score34 First: 24.07.2026 15:00 Last: 24.07.2026 15:00 Sources 1

About this happening: An ongoing DNS poisoning campaign is redirecting traffic from hotel and conference venue Wi‑Fi routers to harvest corporate login credentials, putting traveling employ...

Kratos ecosystem shift changes threat-actor operations

Threat Actor Meta
H score39 First: 22.07.2026 02:07 Last: 22.07.2026 02:07 Sources 1

About this happening: The Kratos phishing-as-a-service ecosystem was dismantled after it scaled to more than 1,800 criminal customers, exposing a subscription model that drove roughly 15,000...

Kali365 Microsoft 365 device-code phishing campaign

Campaign
H score46 First: 25.05.2026 15:45 Last: 25.05.2026 15:45 Sources 1

About this happening: A Kali365 phishing campaign is targeting Microsoft 365 environments worldwide with device-code login lures, putting accounts at risk of token theft and MFA bypas...

EvilTokens Microsoft 365 consent phishing campaign

Campaign
H score39 First: 19.05.2026 14:30 Last: 19.05.2026 14:30 Sources 1

About this happening: The EvilTokens campaign rapidly compromised more than 340 Microsoft 365 organizations across five countries, showing how OAuth grant abuse can bypass MFA and c...

W3LL Microsoft 365 adversary-in-the-middle phishing campaign

Campaign
H score39 First: 13.04.2026 21:55 Last: 13.04.2026 21:55 Sources 1

About this happening: The W3LL phishing operation turned into a high-volume Microsoft 365 credential-theft campaign, exposing more than 17,000 victims worldwide to BEC risk. The kit use...

Timeline

  1. 24.07.2026 20:50 2 articles · 1h ago

    Hotel Wi-Fi DNS hijacking Microsoft 365 phishing campaign

    Initial Disclosure

    Since June, attackers have been altering DNS settings on hotel and conference-center Wi-Fi gateways to send users to fake Microsoft 365 portals. The earliest phase centers on travel and event connectivity, turning public access points into a route for account compromise and document theft.

    Show sources