Hackers hijack hotel and conference Wi-Fi DNS settings to steal Microsoft 365 accounts

Hackers are compromising Wi-Fi gateways at hotels and conference centers and changing their internet settings so travelers are sent to fake Microsoft 365 login pages. ReliaQuest says the campaign has been active since at least June 2026 and has affected organizations across finance, legal, healthcare, energy, retail, and professional services in the U.S., India, Saudi Arabia, and elsewhere. The attackers altered DNS settings, used fake domains including m365-owa[.]com and owa-ms365[.]com, and in some cases abused Microsoft device-code sign-in flows to obtain legitimate OAuth session tokens that can bypass multi-factor authentication.
Why it matters: Traveling employees and conference attendees can have work accounts stolen just by using a compromised venue Wi-Fi network. Organizations should push always-on full-tunnel VPN use, disable device-code authentication where unnecessary, review Microsoft Entra ID logs, and treat hotel or event Wi-Fi as hostile until proven otherwise.

Sources

Hacking Public Wi-Fi DNS to Steal Credentials
Bruce Schneier 2026.08.17 94% relevant
This is the same underlying campaign: attackers compromise public Wi-Fi devices at hotels and conference centers, change DNS settings, and redirect users to fake login pages to steal credentials.
Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts
Bill Toulas 2026.08.04 97% relevant
This is the same underlying Wi-Fi captive-portal attack campaign, but adds Microsoft attribution to Midnight Blizzard/APT29, the campaign name CaptiveCrunch, the Storm-2945 cluster, and new technical details on the CornFlake and ChocoShell malware plus Android targeting and the FruitStone management panel.
Russian hackers hijack hotel Wi-Fi networks to spy on travelers, Microsoft says
2026.08.03 95% relevant
This is a direct update on the same hotel and conference Wi-Fi hijacking campaign, adding Microsoft's attribution to Storm-2945/Midnight Blizzard, naming the CornFlake and ChocoShell malware families, and clarifying that captive-portal redirection and fake update pages are being used against travelers.
Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking
Ionut Arghire 2026.08.03 96% relevant
This source strongly updates the same underlying event by attributing the public Wi-Fi gateway and captive portal credential-theft campaign to Microsoft-tracked Storm-2945, a subgroup of Midnight Blizzard, and by adding details on the CaptiveCrunch operation, associated malware families (CornFlake, ChocoShell, FruitStone), broader hospitality-network compromise, and device-code phishing integrated into the same attack chain.
Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts
Bill Toulas 2026.07.24 100% relevant
This article establishes a distinct ongoing campaign centered on compromised hotel and conference Wi-Fi gateways redirecting users to fake Microsoft 365 authentication flows.
← Back to all stories