Hotel Wi-Fi Phishing Attack Targets Business Travelers with Fake Microsoft Logins
A sophisticated phishing attack is targeting business travelers at hotels and conference centers by compromising Wi-Fi equipment to direct users to fake Microsoft 365 login pages.
The attackers, identified by cybersecurity company ReliaQuest, have been active since at least June and have affected several U.S. cities.
The hackers alter the Domain Name System (DNS) settings of compromised Wi-Fi gateways, which controls how connected devices reach the internet.
When a user tries to access a legitimate Microsoft login page, the compromised gateway may direct their browser to a fake site instead, making it difficult to notice before entering sensitive information.