Hackers are tampering with Wi-Fi equipment at hotels and conference centers, altering Domain Name System settings to redirect travelers to fake Microsoft 365 login pages. Cybersecurity firm ReliaQuest reports the active phishing campaign has targeted organizations across financial services, health care, and retail since June.
A routine internet connection at a hotel or event venue can quickly turn into a trap for traveling employees. According to cybersecurity company ReliaQuest, attackers have been actively tampering with Wi-Fi gateways in several U.S. cities since at least June, turning everyday networks into pathways toward fraudulent sign-in portals.
How Compromised Hotel Gateways Alter DNS Settings
A Wi-Fi gateway manages how devices connected to a local network reach the internet. Once hackers manage to gain administrative access, they can alter the gateway’s Domain Name System (DNS) settings. Because DNS functions as an address book that translates human-readable website names into the numerical IP addresses required to reach specific servers, altering this process lets hackers redirect traffic.
When a traveler attempts to open a legitimate Microsoft sign-in page, the compromised gateway intercepts the request and directs the browser to a fake site instead. Devices often appear to connect normally, showing the familiar hotel network name while other websites continue to load without interruption. This seamless deception makes the attack exceptionally difficult to notice before sensitive credentials are entered.
ReliaQuest researchers have not confirmed the exact method attackers use to initially breach these network appliances. However, potential entry points include exposing administrative tools directly to the internet, weak passwords, vulnerable web dashboards, poorly protected remote management services, or older Wi-Fi appliances running software with known security flaws that venues failed to update promptly.
Fake Microsoft 365 Portals and Device Code Exploits
To harvest business credentials, attackers registered at least four distinct domains for fake Microsoft portals, as identified by ReliaQuest: m365-owa[.]com
, owa-ms365[.]com
, ms365-device[.]com
, and ms365-live[.]com
.
These addresses use familiar terms that busy professionals moving quickly between meetings might easily overlook. When victims enter their Microsoft 365 email addresses and passwords on these fraudulent pages, the stolen accounts expose sensitive business emails, private documents, and company cloud services. Furthermore, hackers can exploit compromised accounts to impersonate employees, opening the door for payment fraud, internal phishing, or downstream attacks against coworkers and clients.
Some incidents involve an even more deceptive device code authentication flow. A user encountering a fake Microsoft page receives an authorization prompt that mimics a legitimate sign-in process. Behind the scenes, the hacker has already initiated an active authentication session. Once the user approves the request, Microsoft issues a valid OAuth token directly to the attacker’s client, granting account access without requiring a stolen password or intercepted one-time code.
Targeted Industries and Multifactor Bypass Risks
The scope of the campaign is notably broad. Organizations connecting through affected equipment span professional services, legal, financial services, health care, energy, and retail sectors. According to ReliaQuest findings, this diverse range of affected industries suggests that attackers are systematically targeting traveling employees rather than focusing on a single vertical market.
The device code technique poses a severe threat because it successfully evades traditional multifactor authentication (MFA) barriers. When the user manually approves the prompt, security systems register a valid authorization because the user initiated the action, even though the session was originally engineered by the attacker.
Travelers who notice login prompts suddenly asking them to approve a device should exercise extreme caution and closely inspect browser address bars and network environments before proceeding.