Hotel WiFi and Microsoft 365 Accounts



How the attack works

  1. Attackers gain administrative access to a public Wi‑Fi gateway.
  2. They alter the gateway's DNS configuration.
  3. When a user tries to access a legitimate Microsoft 365 service, the DNS server returns the attacker's destination instead of Microsoft's.
  4. The user is redirected to a convincing fake Microsoft 365 login page.
  5. Credentials, and in some cases authentication tokens, are stolen.

Why it's dangerous

  • The attack occurs at the network level, not on the victim's device.
  • No phishing email or malicious attachment is required.
  • A single compromised Wi‑Fi gateway can affect many users connected to the network. 

How to protect yourself

  • Avoid entering Microsoft 365 credentials on public Wi‑Fi unless necessary.
  • Use a trusted VPN when on hotel, airport, or conference Wi‑Fi.
  • Verify the browser address bar carefully before signing in.
  • Enable multifactor authentication (MFA).
  • Be cautious of unexpected Microsoft login prompts, especially on public networks. 

For more details, see the reporting from Bleeping Computer: https://www.bleepingcomputer.com/news/security/hackers-hijack-hotel-wi-fi-dns-to-steal-microsoft-365-accounts/. [bing.com]

Comments