Hotel Wi-Fi Networks Under Attack: Hackers Target Business Travelers' Microsoft Logins
Hackers are targeting Microsoft logins through compromised hotel Wi-Fi networks. According to cybersecurity company ReliaQuest, this campaign has been active since at least June and affects several U.S. cities. The attackers change the Domain Name System (DNS) settings on affected Wi-Fi gateways, directing users to fake Microsoft login pages.
The attack is particularly concerning for business travelers who often use hotel Wi-Fi to stay connected while working on the go. Even if a user's device appears to be connected normally, they may unknowingly submit their sensitive information to the hackers' server.
ReliaQuest has identified four domains used by the attackers: m365-owa[.]com, owa-ms365[.]com, ms365-device[.]com, and ms365-live[.]com. These domains contain familiar Microsoft terms, making them difficult to spot as fake.
To protect themselves from this attack, users should consider using a VPN, verifying every Microsoft login address, and being cautious with device code requests.