Protect.Computer
NEWS

Hotel Wi-Fi networks hijacked to steal Microsoft 365 logins

· 1 min read · Network safety Got hacked
Hotel Wi-Fi networks hijacked to steal Microsoft 365 logins

Hackers have been quietly taking over the Wi-Fi routers at hotels and turning them against guests. Since at least June 2026, attackers have been compromising the internet gateways at hotels — particularly across the United States and internationally in India and Saudi Arabia — to redirect travelers to fake Microsoft 365 login pages the moment they try to check email or access work documents. The attack requires no phishing link; simply connecting to hotel Wi-Fi and opening your browser can land you on an impersonation page. Credentials, session cookies, and even multi-factor authentication approvals can all be captured in seconds.

The campaign uses DNS poisoning and a little-known network trick called WPAD (Web Proxy Auto-Discovery) to intercept all web traffic without the guest noticing. Security researchers have linked the tradecraft to APT28 — a Russian military intelligence group with a long history of targeting business travelers. Industries hit include financial services, legal, healthcare, and energy, suggesting attackers are specifically hunting corporate employees away from their usual office network.

How to check if you’re affected

Affected devices are any laptop, phone, or tablet used to access Microsoft 365 while connected to hotel, conference, or other public Wi-Fi networks. Steps you can take right now:

  • Before entering work credentials on any public Wi-Fi, look at the full web address — it should be exactly login.microsoftonline.com, with no extra words or letter swaps.
  • Turn on a VPN before opening any work applications on hotel Wi-Fi. Your employer may already provide one; if not, a reputable personal VPN app creates a secure tunnel that prevents DNS hijacking.
  • Use your phone’s mobile data connection instead of hotel Wi-Fi whenever you need to log into work accounts.
  • If your Microsoft account supports phishing-resistant MFA — such as a hardware security key or number-matching in Microsoft Authenticator — enable it now. Standard SMS codes and push approvals can still be captured by this attack.

Sources

Related reading