Hackers hijack hotel and conference Wi-Fi DNS settings to steal Microsoft 365 accounts

Hackers are compromising Wi-Fi gateways at hotels and conference centers and changing their internet settings so travelers are sent to fake Microsoft 365 login pages. ReliaQuest says the campaign has been active since at least June 2026 and has affected organizations across finance, legal, healthcare, energy, retail, and professional services in the U.S., India, Saudi Arabia, and elsewhere. The attackers altered DNS settings, used fake domains including m365-owa[.]com and owa-ms365[.]com, and in some cases abused Microsoft device-code sign-in flows to obtain legitimate OAuth session tokens that can bypass multi-factor authentication.
Why it matters: Traveling employees and conference attendees can have work accounts stolen just by using a compromised venue Wi-Fi network. Organizations should push always-on full-tunnel VPN use, disable device-code authentication where unnecessary, review Microsoft Entra ID logs, and treat hotel or event Wi-Fi as hostile until proven otherwise.

Sources

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts
Bill Toulas 2026.07.24 100% relevant
This article establishes a distinct ongoing campaign centered on compromised hotel and conference Wi-Fi gateways redirecting users to fake Microsoft 365 authentication flows.
← Back to all stories