💛 A quick favor, if you've got a second.
We're really happy that you chose to read one of our stories and sincerely hope you'll stick around to read more. We took our paywall down — for now — but that won't last forever, and when the gate goes back up, we'd love for you to already be on the inside.
It's free. So please enter your email here and don't forget to like and follow us on all of your favorite Social Media platforms!

A sophisticated phishing operation has weaponized Wi-Fi equipment at hotels and conference centers across multiple U.S. cities to redirect users to counterfeit Microsoft 365 login pages, cybersecurity firm ReliaQuest reported. The campaign, active since at least June, poses particular danger to business travelers who may inadvertently surrender credentials while rushing between meetings. Researchers discovered the attackers had compromised Wi-Fi gateways serving organizations in financial services, professional services, legal, healthcare, energy and retail sectors.
The attack works by allowing hackers to gain administrative control of hotel Wi-Fi gateways and alter their Domain Name System settings. When victims attempt to access legitimate Microsoft login pages, the compromised gateway intercepts the request and redirects browsers to fake sites controlled by attackers. The deception remains difficult to detect because affected devices continue displaying normal Wi-Fi connectivity and other websites load normally, obscuring the malicious redirection until sensitive information has already been entered.
ReliaQuest identified at least four fraudulent domains registered by the attackers that mimic legitimate Microsoft terminology. The stolen Microsoft 365 credentials could expose business email accounts, confidential documents and corporate cloud services. In some cases, attackers exploited device code authentication flows to obtain OAuth tokens that bypass multifactor authentication by manipulating users into approving login requests they did not initiate themselves.
Approximately one-third of incidents involved attempts to abuse Web Proxy Auto-Discovery services, potentially allowing attackers to intercept and manipulate Windows network traffic. Switching to third-party DNS services like Google’s 8.8.8.8 provides insufficient protection because compromised gateways can intercept unencrypted DNS requests before they reach external resolvers. Only encrypted DNS configured in strict mode prevents local gateways from forging responses and redirecting traffic.
Travelers should employ full-tunnel VPN services that encrypt all traffic before connecting to hotel networks. Using a smartphone’s cellular hotspot for sensitive account access avoids the compromised gateway entirely. Users must scrutinize full web addresses before entering passwords and avoid approving unexpected device authentication requests, instead verifying any suspicious prompts directly with company IT departments through trusted channels.
Organizations should disable Microsoft Entra ID device code authentication where business operations do not require it and review login records for unusual geographic locations and unfamiliar devices. IT teams should also disable Web Proxy Auto-Discovery services where unnecessary and investigate unexpected proxy configuration activity on Windows systems. Installing current operating system, browser and security updates before travel closes vulnerabilities that attackers exploit alongside network-based attacks.
More Stories
Bodies of Renowned Climber Nirmal Purja and Three Others Recovered After Broad Peak Avalanche
Oil Slick Expands Around Sanctioned Russian Tanker Stranded Off Oman Coast
Dodgers Land Tigers Ace Skubal in Blockbuster Trade, Reinforcing World Series Favorites