Close Menu
GeekBlog

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Hackers Are Hijacking Hotel Wi-Fi to Steal Microsoft 365 Logins Without a Single Phishing Email

    July 30, 2026

    New York vs Florida: Which State Is Better to Move To?

    July 30, 2026

    What State Is Best to Invest in Real Estate in 2026?

    July 30, 2026
    Facebook X (Twitter) Instagram Threads
    GeekBlog
    • Home
    • Mobile
    • Tech News
    • Blog
    • How-To Guides
    • AI & Software
    Facebook
    GeekBlog
    Home»Tech News»Hackers Are Hijacking Hotel Wi-Fi to Steal Microsoft 365 Logins Without a Single Phishing Email
    Tech News

    Hackers Are Hijacking Hotel Wi-Fi to Steal Microsoft 365 Logins Without a Single Phishing Email

    Marcus BennettBy Marcus BennettJuly 30, 20267 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Laptop screen showing a cyber security alert, representing a hijacked hotel Wi-Fi login attempt
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link

    Business travelers do the same thing without thinking about it. Check into the hotel, open the laptop, tap the network name from the list, type in a room number or a last name, and get back to work. That habit is exactly what a new wave of attacks is counting on. Security researchers have found that hotel and conference center Wi-Fi networks in multiple countries have been quietly hijacked to steal Microsoft 365 logins from the very people who trust that connection most: employees on the road.

    What makes this campaign worth paying attention to is not just who it is hitting, but how little it asks of the victim. There is no phishing email to fall for, no attachment to open, and no malware to install. The trap is built into the network itself, and by the time a laptop connects, the damage is already in motion.

    The Attack Lives in the Router, Not Your Inbox

    Researchers at ReliaQuest and Microsoft have been tracking compromised Wi-Fi gateways across hotels and conference venues in the United States, India, and Saudi Arabia since at least June 2026. The entry point is mundane: many of these properties run small office and home office grade routers to handle guest Wi-Fi, and those devices often ship with exposed management interfaces such as SSH, SNMP, or a web admin panel, sometimes still sitting behind default or reused passwords. Once an attacker gets administrative access to one of these gateways, they do not need to touch a single guest device directly. They just change the DNS settings.

    That single change is what makes the attack so effective. A Wi-Fi gateway handles DNS lookups for every device that connects to it, translating a typed address into the server it actually reaches. Poison that lookup table, and a guest can type “microsoft.com” into their browser with perfect accuracy and still land on a server the attacker controls. The address bar shows nothing wrong, because nothing about the request itself is wrong. Only the destination has quietly changed hands.

    Skipping the Password Entirely

    Once a guest’s traffic is being redirected, the attackers do not simply throw up a fake login box and hope someone types a password into it, though that has been part of the campaign too, using lookalike domains such as m365-owa.com, owa-ms365.com, and ms365-live.com to mimic genuine Microsoft sign-in pages. The more concerning technique researchers flagged is narrower and harder to spot: abuse of Microsoft’s device code authentication flow.

    Recommended for you:

    Microsoft’s Biggest Patch Tuesday Ever Just Showed Us Where Cybersecurity Is Heading
    Tech News·Jul 29, 2026

    Microsoft’s Biggest Patch Tuesday Ever Just Showed Us Where Cybersecurity Is Heading

    Device code login exists for a legitimate reason. It lets someone sign into a Microsoft account on a device with no keyboard or browser, a smart TV or a conference room console, by generating a short code that gets approved from a phone or laptop that is already logged in. Attackers have been exploiting that flow by prompting a hijacked session to generate a device code request, then getting the victim to unknowingly approve it. The victim never hands over a password. They just click approve on something that looks like a routine sign-in prompt, and the attacker walks away with a valid OAuth token, enough to access the account without needing a password or a one-time code at all. It is a textbook example of how multi-factor authentication, while still worth having, is not the finish line security teams sometimes treat it as.

    Familiar Fingerprints Point to a Familiar Actor

    The tradecraft here is not new so much as it is recycled and refined. Investigators say this campaign carries strong hallmarks of FrostArmada, a set of activity previously linked to APT28, also tracked under the names Forest Blizzard and Fancy Bear, a military intelligence unit widely attributed to Russia’s GRU. Gateway-level DNS hijacking, domains built to impersonate Microsoft’s login infrastructure, and a downstream adversary-in-the-middle style compromise of Microsoft 365 accounts all line up with tactics this group has used before against routers and edge devices. What has changed is the target list. Instead of picking off known offices or specific individuals, this version goes after the physical spaces where corporate employees briefly let their guard down, hotel lobbies, conference centers, the kind of shared, semi-public network everyone assumes is safe enough for checking email.

    The victim list reflects that shift in strategy. Confirmed and suspected targets span financial services, legal, healthcare, energy, retail, and professional services firms, spread across multiple U.S. cities as well as locations in India and Saudi Arabia. None of that requires a targeted spear-phishing email tailored to one employee. It just requires that employee to book a hotel room in the wrong building during the wrong week.

    Why This Keeps Happening at the Network Level

    It is tempting to treat this as a hotel industry problem, but the honest read is broader than that. Hospitality Wi-Fi has always been an awkward mix of convenience and neglect. Properties want guests online in seconds with no friction, so captive portals are simple by design, and the routers behind them are frequently installed once and left alone for years, patched rarely if ever. That combination, wide deployment plus weak maintenance, is exactly the profile a state-linked group looks for when it wants a foothold that can sit quietly for months. It also echoes a pattern security teams have been noticing across other everyday infrastructure lately, from smart building systems to license plate readers that are being quietly upgraded into far more capable tracking tools, where equipment nobody thinks of as a security asset ends up handling a surprising amount of sensitive traffic and data.

    What Actually Stops This

    For IT and security teams, the single most effective fix is not user training, it is a configuration change. Microsoft Entra Conditional Access supports an authentication flows condition that can block the device code grant entirely for users who have no genuine business need for it, which describes the overwhelming majority of a typical workforce. Where the flow is genuinely required, restricting it to trusted networks and locations closes most of the gap. Security teams should also treat any suspected compromise as more than a password reset, since an attacker holding a valid OAuth token keeps working even after the password changes, until sessions are explicitly revoked.

    Recommended for you:

    DeepMind’s Demis Hassabis Wants a Wall Street-Style Watchdog for AI
    Tech News·Jul 28, 2026

    DeepMind’s Demis Hassabis Wants a Wall Street-Style Watchdog for AI

    Business travelers have a simpler, if less complete, set of options. A trustworthy VPN encrypts and reroutes traffic before a compromised gateway ever gets a chance to redirect it, which neutralizes DNS poisoning at the source. It is also worth treating any unexpected device code prompt, especially one that appears without you having just tried to sign into a TV, kiosk, or similar screen, as a red flag rather than a routine click. None of this requires becoming a security expert. It just requires knowing that the free Wi-Fi at check-in is no longer the safest weak link in the chain, the router quietly running it might be.

    Microsoft’s own security calendar this year has already been unusually heavy, including a record-setting Patch Tuesday that fixed 570 vulnerabilities in a single release, a reminder that the volume of both offense and defense in this space keeps climbing. Industry responses are shifting too. Telecom carriers facing their own run of state-linked intrusions recently broke years of competitive habit to form a joint threat-sharing group, eight rival companies pooling intelligence through the new C2 ISAC, which suggests more industries may need that same kind of coordinated defense as attackers keep finding ordinary infrastructure to exploit. Hospitality could well be next in line.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
    Previous ArticleNew York vs Florida: Which State Is Better to Move To?
    Marcus Bennett

      Marcus Bennett is GeekBlog's Android expert, covering everything from Google's Pixel line and Samsung Galaxy flagships to OnePlus, Nothing, Xiaomi and the broader Android ecosystem. He follows each Android OS release, One UI and Pixel Feature Drop, custom ROMs and the foldable wave, translating spec sheets and beta builds into hands-on guidance for readers choosing their next Android phone, tablet or wearable.

      Related Posts

      5 Mins Read

      Microsoft’s Biggest Patch Tuesday Ever Just Showed Us Where Cybersecurity Is Heading

      6 Mins Read

      DeepMind’s Demis Hassabis Wants a Wall Street-Style Watchdog for AI

      3 Mins Read

      Eye Drops That Dissolve Cataracts Without Surgery? The Australian Breakthrough That Isn’t

      7 Mins Read

      Crashing the Boys’ Club: Why Cybersecurity Is Finally Opening Its Doors to Career Changers

      6 Mins Read

      Telecom Giants Form C2 ISAC to Fight the Next Salt Typhoon

      11 Mins Read

      Is There an Alternative to Google? 9 Best Picks (2026)

      Top Posts

      Japan Skips Exams Until Age 10 and Teaches Character Instead. The Results Are Complicated.

      July 29, 20268 Views

      Husbands Cause More Stress Than Kids? Science Says Many Moms Feel Exactly That

      July 28, 20268 Views

      How to Block Twitch Ads with uBlock Origin (2026 Guide)

      June 15, 20267 Views
      Stay In Touch
      • Facebook

      Subscribe to Updates

      Get the latest tech news from FooBar about tech, design and biz.

      Most Popular

      Best Stores for Buying MP3 and Digital Music You Can Keep Forever (2026)

      August 2, 2025904 Views

      Discord will require a face scan or ID for full access next month

      February 9, 2026770 Views

      Trade in your old phone and get up to $1,100 off a new iPhone 17 at AT&T – here’s how

      September 10, 2025382 Views
      Our Picks

      Hackers Are Hijacking Hotel Wi-Fi to Steal Microsoft 365 Logins Without a Single Phishing Email

      July 30, 2026

      New York vs Florida: Which State Is Better to Move To?

      July 30, 2026

      What State Is Best to Invest in Real Estate in 2026?

      July 30, 2026

      Subscribe to Updates

      Get the latest creative news from FooBar about art, design and business.

      Facebook
      • About Us
      • Contact us
      • Privacy Policy
      • Disclaimer
      • Terms and Conditions
      © 2026 GeekBlog

      Type above and press Enter to search. Press Esc to cancel.