securityonline.info 7/30/2026, 8:21:27 AM · external

Hackers use hotel WiFi to redirect staff to fake Microsoft pages

Hackers use hotel WiFi to redirect staff to fake Microsoft pages
CyberSIXT Evidence Panel
Primary Source reliaquest.com

A recent report by ReliaQuest details a cyber attack where intruders compromised hotel and conference center Wi-Fi gateways to poison DNS and redirect traffic to fraudulent Microsoft pages, targeting corporate employees. Initial access likely occurred via weak admin credentials on exposed management interfaces. The campaign has been active since at least June 2026, with multiple gateways compromised across the US, India, and Saudi Arabia.

Despite operating without requiring user interaction, the threat remains ongoing, as attackers exploit device-code flow and auto-discovery protocols. To mitigate risks, organizations are advised to implement full-tunnel VPNs, enforce strict-mode encrypted DNS, and educate traveling staff about security best practices.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline