Hackers have compromised Wi-Fi equipment in hotels and conference centers across multiple U.S. cities, redirecting users to fake Microsoft 365 login pages. The campaign, active since at least June, targets business travelers by altering Domain Name System (DNS) settings on affected Wi-Fi gateways.
The cybersecurity firm ReliaQuest identified compromised networks in several major cities, including those used by organizations in financial services, professional services, legal, health care, energy, and retail. Researchers noted that the broad industry involvement suggests the attackers may be focusing on traveling employees rather than targeting a single sector.
How the attack works
A Wi-Fi gateway controls how connected devices access the internet. Once hackers gain administrative access, they can modify the gateway’s DNS settings, which function like an internet address book. In this campaign, attackers alter these settings to redirect users to counterfeit Microsoft sign-in pages when they attempt to access legitimate services. The fake login pages closely resemble the real Microsoft 365 interface, increasing the risk of credential theft.
Warning signs and protective measures
ReliaQuest has outlined steps travelers can take to reduce risk. Users should verify the URL of any login page before entering credentials, ensuring it begins with https:// and matches the official Microsoft domain. Travelers are also advised to use virtual private networks (VPNs) to encrypt their internet traffic and avoid logging into sensitive accounts on public Wi-Fi networks. Additionally, enabling multi-factor authentication (MFA) can provide an extra layer of security even if credentials are compromised.
The campaign highlights the ongoing challenge of securing public Wi-Fi networks, particularly in high-traffic locations like hotels and conference centers. Cybersecurity experts recommend that organizations educate employees on safe Wi-Fi practices and implement policies restricting sensitive logins to trusted networks.