Alert For Business Travelers: Hotel Wi-Fi Is Hijacking Microsoft 365 Accounts
Compromised hotel networks redirect logins to fake pages while Big Tech stays quiet on the risks
Business travelers logging into hotel and conference center Wi-Fi are getting hit by a quiet campaign that steals Microsoft 365 accounts. Attackers take over the hotel’s Wi-Fi gateways, change the DNS settings, and redirect people straight to fake Microsoft login pages. No phishing email needed. No malware on the laptop at first. Just connect to the free Wi-Fi and type in your company credentials.
Security firm ReliaQuest first flagged the activity in July. Compromised gateways showed up in multiple U.S. cities plus India and Saudi Arabia. The campaign has been running since at least June and hits people in finance, law, healthcare, energy, and retail—exactly the kind of people who travel for work and rely on Microsoft 365 every day.
Microsoft later tied the operation to Storm-2945, a subgroup of the Russian state-backed Midnight Blizzard group. In some cases the hackers go further and push malware onto devices, giving them keyloggers, remote access, and the ability to steal more passwords and tokens. They even abuse Microsoft’s own device-code login flow so they can slip past multi-factor authentication.
This should make every company that locked itself into Microsoft’s cloud take a hard look. Big Tech companies sell the idea that their systems are locked down tight. Yet a simple takeover of a hotel router is enough to funnel people into fake Microsoft pages and walk away with valid accounts. Travelers are told to trust the big platforms, but the weakest link ends up being the free Wi-Fi those same platforms never control.
The practical advice is straightforward: Skip hotel Wi-Fi when possible. Use a phone hotspot or a trusted VPN that tunnels everything. Treat public networks as hostile. And maybe stop assuming that handing more of your business to one giant tech company makes anything safer.
Companies that keep putting all their eggs in the Microsoft basket need to wake up to the real-world risks instead of the marketing slides.
Sources - more reading
https://reliaquest.com/blog/threat-spotlight-dns-poisoning-tactics-expand-to-hospitality/
https://www.securityweek.com/russian-state-apt-linked-to-recent-public-wi-fi-gateway-hacking/
https://therecord.media/russian-wifi-hackers-hotels
https://cyberinsider.com/microsoft-links-hotel-wi-fi-hacks-to-russian-midnight-blizzard-hackers/