Threats

Microsoft 365 Account Hijacking via Hotel Wi-Fi DNS

July 24, 2026 20:04 · 12 min read
Microsoft 365 Account Hijacking via Hotel Wi-Fi DNS

Hotel Wi-Fi DNS Hijacking Campaign Targets Microsoft 365 Accounts

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. The campaign, which has been ongoing since at least June, impacts organizations in various sectors, including financial services, professional services, legal, health care, energy, and retail.

Cybersecurity company ReliaQuest identified compromised Wi-Fi gateways in multiple U.S. cities as well as other regions of the world, such as India and Saudi Arabia. Since the devices serve corporate events, hijacking the Microsoft 365 accounts could give attackers access to sensitive business information, communications, and private documents.

Attack Chain and Methodology

It is unclear how initial access to the Wi-Fi appliances was gained, but ReliaQuest says the threat actor could have exploited weakly protected, exposed management interfaces (e.g., SSH, SNMP, web admin dashboards) or vulnerabilities. Once the attacker gains administrator access, they can modify the gateway’s DNS settings to redirect connections to legitimate domains to infrastructure under the attacker's control.

ReliaQuest says that the attacker registered at least four domains for setting up fake Microsoft login portals: m365-owa[.]com, owa-ms365[.]com, ms365-device[.]com, and ms365-live[.]com. With DNS settings changed, users trying to access legitimate Microsoft login portals would land on the hacker's phishing pages and enter their credentials.

Bypassing Multi-Factor Authentication (MFA) Protection

In some cases, the researchers observed a device-code authentication flow in which targets were redirected to a fake Microsoft page with a prompt. Authorizing the attacker-initiated request causes a legitimate OAuth token to be issued to the attacker's client, bypassing the MFA protection without stealing any credentials or intercepting access tokens.

The attack steps, as outlined by ReliaQuest, involve modifying the DNS settings, redirecting users to fake login pages, and obtaining a legitimate OAuth token through the device-code authentication flow.

Additional Attack Vectors

In roughly one-third of the investigated cases, the attackers also attempted to abuse Web Proxy Auto-Discovery (WPAD) by responding to Windows' automatic WPAD lookup with a malicious proxy auto-configuration (PAC) file. This would theoretically route traffic from Windows apps, including Chrome, through an attacker-controlled proxy.

Recommendations for Protection

ReliaQuest recommends using an always-on, full-tunnel VPN and encrypted DNS in strict mode as solid protection measures against these attacks. Additionally, the cybersecurity company recommends disabling WPAD, reviewing logs for suspicious activity, and disabling Device Code authentication flow in Microsoft Entra ID when not needed.

As emphasized by ReliaQuest, using public DNS servers such as Google’s 8.8.8.8 does not prevent this attack, as the gateway forges the plain-text requests before they reach the intended resolver.

Conclusion

The hijacking of hotel Wi-Fi DNS settings to steal Microsoft 365 accounts is a significant threat to organizations across various sectors. By understanding the attack chain and methodology, as well as taking the recommended protection measures, organizations can reduce the risk of falling victim to these attacks.

Security teams should prioritize testing every layer of their security infrastructure to ensure that threats are detected and prevented before they can cause harm. The Picus whitepaper provides guidance on how breach and attack simulation tests can be used to evaluate the effectiveness of SIEM and EDR rules.


Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free