Close Menu
NCIJ Network NCIJ Network
    What's Hot

    NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats

    July 25, 2026

    Quantum Roadmap Would Push Bitcoin Much Higher: Charles Edwards

    July 25, 2026

    New giant salamander species discovered in 3.5-million-year-old fossils

    July 25, 2026
    Facebook X (Twitter) Instagram
    Trending
    • NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats
    • Quantum Roadmap Would Push Bitcoin Much Higher: Charles Edwards
    • New giant salamander species discovered in 3.5-million-year-old fossils
    • Christopher Nolan has made an Odyssey for our times – by sacrificing the delicious darkness of Homer’s epic | Charlotte Higgins
    • Live: France orders evacuations near Bordeaux as wildfires sweep through southwest
    • At Correspondents’ Dinner, a Rambling Trump Hurls Insults
    • SpaceX launches new V3 Starlink satellites but suffers another booster failure
    • Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, July 25
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 25, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages.

    The campaign has been ongoing since at least June and impacts organizations in various sectors, including financial services, professional services, legal, health care, energy, and retail.

    Cybersecurity company ReliaQuest identified compromised Wi-Fi gateways in multiple U.S. cities as well as other regions of the world, such as India and Saudi Arabia.

    image

    Since the devices serve corporate events, hijacking the Microsoft 365 accounts could give attackers access to sensitive business information,  communications, and private documents.

    “We observed traffic to these compromised gateways from organizations in a range of industries, including financial services, professional services, legal, health care, energy, and retail- confirming this isn’t sector-specific targeting, but a campaign that highly likely goes after traveling employees wherever they connect,” ReliaQuest says.

    The researchers believe this activity is similar to the FrostArmada router-based campaigns attributed to the Russian espionage group APT28 (a.k.a. Fancy Bear, Forest Blizzard).

    Attack chain

    It is unclear how initial access to the Wi-Fi appliances was gained, but ReliaQuest says the threat actor could have exploited weakly protected, exposed management interfaces (e.g., SSH, SNMP, web admin dashboards) or vulnerabilities.

    Once the attacker gains administrator access, they can modify the gateway’s DNS settings to redirect connections to legitimate domains to infrastructure under the attacker’s control.

    ReliaQuest says that the attacker registered at least four domains for setting up fake Microsoft login portals: m365-owa[.]com, owa-ms365[.]com, ms365-device[.]com, and ms365-live[.]com.

    With DNS settings changed, users trying to access legitimate Microsoft login portals would land on the hacker’s phishing pages and enter their credentials.

    In some cases, the researchers observed a device-code authentication flow in which targets were redirected to a fake Microsoft page with a prompt.

    “What the user can’t see is that approving the prompt authorizes a session initiated by the attacker,” ReliaQuest says. The researchers note that authorizing the attacker-initiated request causes a legitimate OAuth token to be issued to the attacker’s client.

    This bypasses the multi-factor authentication (MFA) protection without stealing any credentials or intercepting access tokens.

    The attack steps
    The attack steps
    Source: ReliaQuest

    In roughly one-third of the investigated cases, the attackers also attempted to abuse Web Proxy Auto-Discovery (WPAD) by responding to Windows’ automatic WPAD lookup with a malicious proxy auto-configuration (PAC) file.

    This theoretically would route traffic from Windows apps, including Chrome, through an attacker-controlled proxy, but ReliaQuest couldn’t confirm that these attacks were successful.

    The researchers also emphasized that using public DNS servers such as Google’s 8.8.8.8 does not prevent this attack, as the gateway forges the plain-text requests before they reach the intended resolver.

    ReliaQuest recommends using an always-on, full-tunnel VPN and encrypted DNS in strict mode as solid protection measures against these attacks.

    Additionally, the cybersecurity company recommends disabling WPAD, reviewing logs for suspicious activity, and disabling Device Code authentication flow in Microsoft Entra ID when not needed.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    Accounts DNS hackers hijack hotel Microsoft Steal WiFi
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats

    AegisAI Raises $36 Million for AI-Powered Email Security

    Golden Chickens Resurfaces With Four New Malware Families and Modular Implants

    I fixed my home office’s spotty Wi-Fi with Samsung’s free diagnostic tool – and it took just minutes

    In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws

    Escape Artists: ‘Incorrigible’ AI Models Resist Rehabilitation

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats

    July 25, 2026

    Quantum Roadmap Would Push Bitcoin Much Higher: Charles Edwards

    July 25, 2026

    New giant salamander species discovered in 3.5-million-year-old fossils

    July 25, 2026

    Christopher Nolan has made an Odyssey for our times – by sacrificing the delicious darkness of Homer’s epic | Charlotte Higgins

    July 25, 2026
    Latest Posts

    Trump slaps 50% tariffs on Canada and Carney vows to ‘intensify’ trade talks

    July 21, 2026

    How Two Brothers Dug for Dead Relatives: With a Shovel and a Kitchen Knife

    July 21, 2026

    Chile floods: Towns evacuated following heavy rain in Coquimbo

    July 21, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats

    July 25, 2026

    Quantum Roadmap Would Push Bitcoin Much Higher: Charles Edwards

    July 25, 2026

    New giant salamander species discovered in 3.5-million-year-old fossils

    July 25, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.