Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Logins, Bypass MFA
Executive Briefing
- Targets compromised hotel and conference Wi-Fi gateways to redirect users to fake Microsoft 365 login pages
- Campaign active since at least June, affecting financial, legal, healthcare, and energy sector travelers across U.S. cities
- Exploits device code authentication flow to bypass multifactor authentication by tricking users into approving attacker-initiated sessions
- Attackers registered fake domains mimicking Microsoft portals to harvest credentials and OAuth tokens
- Switching to public DNS alone does not block the attack; encrypted DNS in strict mode or a full-tunnel VPN is recommended
Sponsored