Exclusive Student Offer

Prime for Young Adults

Get a 6-month trial with premium college perks & fast delivery.

Start Free Trial
Listen Anywhere

Audible Standard Trial

Get 30 days of audiobooks free. Cancel anytime, keep your books.

Claim Free Books

Wi-Fi Attacks in Hotels: Hackers Target Microsoft 365 Accounts via Gateways

Security researchers from ReliaQuest have identified an ongoing cyber campaign specifically targeting business travelers at hotels and conference centers. In these attacks, cybercriminals compromise the infrastructure of Wi-Fi gateways to intercept and take over Microsoft 365 account credentials. These attacks have been observed across various regions and industries, raising alarms about the vulnerabilities associated with public Wi-Fi networks.

Weak Credentials as Gateways

According to findings by ReliaQuest, attackers exploit vulnerabilities in so-called captive portal devices—interfaces that users typically encounter when logging into public or semi-private networks. Access to these devices is often gained through weak administrator credentials, particularly via protocols like SSH or SNMP, as well as through web-based configuration consoles.

Once control over a gateway is obtained, attackers utilize DNS poisoning techniques. This allows them to redirect user traffic selectively. Instead of connecting to legitimate services, victims are led to fake login pages for Microsoft 365. Four specific malicious domains have been identified in this context: m365-owa.com, owa-ms365.com, ms365-device.com, and ms365-live.com.

Bypassing Multi-Factor Authentication

A central feature of this campaign is the misuse of the so-called Device Code Flow. This function is initially intended for registering devices with cloud services that lack an easy input method. However, attackers hijack this process to bypass security measures like Multi-Factor Authentication (MFA).

Additionally, researchers observed that around one-third of the analyzed cases involved abuse of the Web Proxy Auto-Discovery (WPAD) protocol. The technical characteristics and tactics utilized are reportedly similar to those of the infamous APT28 group, also known as Fancy Bear or FrostArmada, which has historically targeted high-profile organizations.

Affected Regions and Industries

The campaign has been active since June 2026, with geographic hotspots in the USA, India, and Saudi Arabia. The attacks are not limited to a single industry but have affected various sectors, including finance and law, healthcare, energy, and retail.

Specific IP addresses associated with the attackers’ infrastructure have also been identified: 38.146.28.75, 31.57.243.154, and 104.194.159.150.

Recommended Protective Measures for Businesses

Given the sophistication and professionalism of these attacks, experts recommend enhanced security precautions for employees on business trips. Key measures include the consistent use of full-tunnel VPN connections, which encrypt all data traffic and protect against local network manipulations.

Furthermore, it is advisable to implement encrypted DNS and to disable the WPAD protocol on corporate devices. To mitigate the specific account takeover methods, organizations should also consider blocking the Device Code Flow in their cloud security policies unless it is essential for business operations.

By implementing these measures and maintaining vigilance, companies can significantly reduce their risk of falling victim to these targeted cyber attacks.

Get Audible 30-Day Free Trial

As an Amazon Associate, we earn from qualifying purchases.