By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Hackers Hijack Hotel Wi-Fi DNS for Microsoft 365 Account Theft
Cybercriminals are actively exploiting vulnerabilities in hotel Wi-Fi networks by manipulating Domain Name System (DNS) settings to redirect users to fraudulent Microsoft 365 login pages. This sophisticated phishing tactic aims to harvest sensitive user credentials, including usernames and passwords, for Microsoft 365 accounts. The attack vector targets individuals connecting to public Wi-Fi at hotels and conference centers, environments often frequented by business professionals who rely heavily on cloud-based productivity suites.
Researchers at Proofpoint identified this ongoing campaign, detailing how attackers gain control of the DNS settings on Wi-Fi devices within these hospitality venues. Once compromised, these devices are configured to resolve legitimate Microsoft 365 domain requests to IP addresses controlled by the attackers. Users attempting to access their Microsoft 365 services are then presented with a convincing replica of the official login portal, designed to trick them into entering their credentials. The stolen information can then be used for further malicious activities, including unauthorized access to company data, financial fraud, or identity theft.
The campaign highlights a persistent threat to users connecting to unsecured or inadequately secured public networks. While the specific group behind this operation has not been publicly named, the methodology suggests a well-resourced threat actor with a clear objective of compromising business accounts. The attackers are leveraging the trust users place in seemingly legitimate network infrastructure to execute their phishing schemes. This method bypasses traditional email-based phishing by directly intercepting network traffic and presenting a deceptive login experience at the point of access.
To mitigate this risk, cybersecurity experts advise users to exercise extreme caution when connecting to public Wi-Fi networks, especially for sensitive transactions or accessing critical business applications. Employing a Virtual Private Network (VPN) is strongly recommended as it encrypts internet traffic, making it significantly harder for attackers to intercept or manipulate DNS requests. Additionally, users should always verify the URL of login pages and be wary of any unexpected redirects or prompts for credentials, particularly when accessing services like Microsoft 365. Organizations are also urged to educate their employees about these evolving threats and reinforce secure connectivity practices.
Original source — read the full reporting at the publisher:
Read on BleepingComputerGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.