The hotel Wi-Fi DNS hijacking campaign highlights a serious risk for business travelers: the network you connect to can become part of the phishing attack.

Attackers are reportedly compromising Wi-Fi infrastructure at hotels and conference centers and changing DNS settings to redirect users toward fake Microsoft 365 login pages. That means the victim may type or visit what they believe is a normal Microsoft login flow, but the compromised network silently points them toward attacker-controlled infrastructure.

This is especially dangerous because it attacks trust at the network layer. Users are trained to avoid suspicious links, unknown attachments, and strange domains. But in a DNS hijacking scenario, the user may not begin from a suspicious email at all. They may simply connect to hotel Wi-Fi, open the browser, and attempt to sign in to Microsoft 365 like they do every day.

The risk is high because Microsoft 365 accounts are extremely valuable. A compromised account can expose email, Teams chats, OneDrive files, SharePoint documents, calendars, contacts, invoices, contracts, HR records, customer data, and internal business communication. It can also become a launchpad for phishing, business email compromise, data theft, lateral movement, and fraud.

For executives, sales teams, consultants, auditors, support teams, developers, finance users, and administrators, this type of attack can be particularly damaging. These users often travel, connect from hotels and conferences, and access sensitive corporate services from laptops. Attackers understand that hotel networks are full of targets carrying work devices, cloud accounts, VPN access, and just enough travel fatigue to click through things quickly. Humanity bravely invented business travel and then connected it to public Wi-Fi. Bold strategy.

This attack also shows why public Wi-Fi should not be treated as trusted infrastructure. A hotel network may have a familiar name, a password at the front desk, and a polished captive portal, but that does not mean its routers, access points, DNS settings, or gateway devices are secure. Hospitality networks often involve many devices, vendors, contractors, legacy systems, and shared administration practices, making them attractive targets.

Users should avoid signing in to critical business accounts directly over hotel or conference Wi-Fi unless a trusted security layer is active. A full-tunnel corporate VPN can help by routing DNS and web traffic through trusted infrastructure instead of the local hotel network. Split-tunnel configurations may not provide the same protection if DNS or Microsoft 365 traffic still exits through the local network.

Organizations should enforce always-on VPN for managed devices, especially for users who travel. DNS requests should be routed through trusted corporate resolvers, security gateways, or secure web gateways. Devices should not be allowed to silently accept DNS settings from untrusted networks for sensitive business access.

Browser warnings must be taken seriously. Users should never ignore certificate errors, unusual login pages, unexpected MFA prompts, strange domain names, or repeated requests to sign in. If the login page looks different, loads from an unfamiliar domain, or appears immediately after joining public Wi-Fi, users should stop and verify before entering credentials.

Multifactor authentication remains important, but it is not a complete defense against modern phishing. Adversary-in-the-middle phishing pages can capture passwords, session cookies, and sometimes MFA responses in real time. Organizations should move toward phishing-resistant MFA such as FIDO2 security keys, passkeys, or certificate-based authentication where possible.

Conditional access policies are also important. Microsoft 365 access should be evaluated based on device compliance, location risk, sign-in risk, impossible travel, unfamiliar networks, unmanaged devices, and session behavior. A password and MFA prompt alone should not be enough to grant broad access from a risky environment.

Security teams should monitor for unusual Microsoft 365 sign-ins from hotel networks, foreign locations, anonymization services, unfamiliar autonomous systems, or impossible travel patterns. They should also watch for new inbox rules, suspicious OAuth app consent, mailbox forwarding, mass downloads from OneDrive or SharePoint, new device registrations, and abnormal Teams or email activity after travel.

If a user entered credentials while connected to a suspicious hotel or conference Wi-Fi network, the response should be immediate. The account password should be reset from a trusted network and clean device, active sessions should be revoked, MFA methods should be reviewed, suspicious tokens should be invalidated, and Microsoft 365 audit logs should be checked for unauthorized access.

Organizations should also train employees that public Wi-Fi risk is no longer only about someone “sniffing traffic.” Modern attacks may involve DNS manipulation, captive portal abuse, rogue access points, compromised routers, fake login pages, and session theft. The attacker does not need to break encryption if they can trick the user into authenticating to the wrong place.

For hotels, conference centers, and managed Wi-Fi providers, this incident is a reminder that guest Wi-Fi infrastructure is security infrastructure. Routers, gateways, DNS settings, captive portals, access points, and management consoles must be patched, monitored, locked down, and protected with strong administrator authentication.

Default passwords, exposed management panels, outdated router firmware, weak remote administration, and unmanaged DNS settings create risk not only for the venue, but also for every guest who connects. A hotel network compromise can become a credential-theft platform at scale.

Businesses should provide traveling employees with clear guidance: use mobile hotspot where possible, use always-on VPN, avoid sensitive logins on public Wi-Fi, verify domains carefully, never bypass certificate warnings, and report unusual login behavior immediately.

The key lesson is that identity security does not stop at the cloud login page. The network path to that login page matters. If DNS can be hijacked, users can be quietly pushed toward credential theft even when they believe they are accessing a trusted service.

Hotel Wi-Fi is convenient, but convenience is not trust. Organizations should assume public networks are hostile, protect Microsoft 365 access with phishing-resistant controls, route traffic through trusted security layers, and monitor accounts closely after travel.

Attackers are targeting the point where tired users, public Wi-Fi, and cloud identity meet. That is a very human weak spot, which means it will keep being abused until organizations design controls that do not depend on every traveler becoming a DNS expert before breakfast.


Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]

Source: Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts via Bleeping Computer — published 24 Jul 2026.