AUTO-UPDATED

Hackers are compromising hotel Wi-Fi gateways to hijack Microsoft 365 accounts

Threat actors are compromising public Wi-Fi gateways at hotels and conference centers to silently hijack Microsoft 365 accounts by redirecting user traffic through malicious DNS poisoning attacks.

Key Points

  • ReliaQuest researchers identified attackers exploiting weak gateway credentials to intercept traffic without needing to compromise individual user devices.
  • The campaign targets users across various sectors, including finance, legal, and healthcare, with incidents reported in the United States, India, and Saudi Arabia.
  • Attackers use fraudulent domains like m365-owa[.]com to impersonate Microsoft login pages and steal credentials from unsuspecting travelers.
  • Standard security measures like using public DNS providers or DNSSEC are insufficient because they do not encrypt traffic or prevent gateway-level interception.
  • Experts recommend using full-tunnel VPNs, disabling automatic proxy discovery, and enforcing strict conditional access policies to mitigate these network-level risks.

Why it Matters

This attack vector highlights a critical vulnerability in how corporate devices trust local network infrastructure, potentially leading to significant data exfiltration from enterprise accounts. By bypassing endpoint security, these gateway compromises force organizations to rethink their reliance on public Wi-Fi and prioritize encrypted, end-to-end traffic tunnels for remote employees.
Computerworld Published by Taryn Plumb
Read original