Hotel Wi-Fi Hacked to Steal Microsoft Logins
Hackers are targeting Microsoft logins by tampering with Wi-Fi equipment at hotels and conference centers. The compromised network may direct users to fake Microsoft 365 login pages, capturing business logins and potentially exposing sensitive information.
The attack, which has been active since at least June, affects various industries including financial services, professional services, legal, healthcare, energy, and retail. Researchers found compromised Wi-Fi gateways in several U.S. cities, suggesting the hackers may be targeting traveling employees rather than a specific industry.
The attackers change the DNS settings on the gateway to direct users to fake login pages. They also use device code prompts that appear legitimate but bypass multifactor authentication. In some cases, they attempt to abuse Web Proxy Auto-Discovery (WPAD) to manipulate network activity.