Hotel Wi-Fi Phishing Attack Targets Business Travelers with Fake Microsoft Logins
Hackers have been targeting hotels and conference centers by tampering with Wi-Fi equipment to redirect guests to fake Microsoft 365 login pages. This campaign, which has been active since at least June, poses a significant risk to business travelers, particularly in the financial services, professional services, legal, health care, energy, and retail industries.
The attackers change the DNS settings of compromised Wi-Fi gateways, allowing them to direct browsers to fake login pages without users noticing. The hackers have registered at least four domains for their fake portals, which contain familiar Microsoft terms to make them appear legitimate.
Researchers from ReliaQuest identified several possible entry points for the attackers, including weak passwords and vulnerable web dashboards. Once inside, the hacker can change the DNS configuration without touching each guest's phone or laptop. One compromised gateway can affect many people who connect during an event.