
Hotels’ Wi‑Fi Gateways Become Phishing Vectors for Microsoft 365 Logins
Hackers are hijacking hotel and conference Wi‑Fi gateways to redirect business travelers to fake Microsoft 365 sign‑in pages, potentially bypassing MFA via deceptive device prompts and WPAD abuse. Active since at least June, the campaign alters DNS to serve phishing domains (e.g., m365-owa.com, ms365-live.com) and can affect many industries; defenses include using a full‑tunnel VPN, a mobile hotspot, verifying login URLs, avoiding unexpected prompts, updating devices, and having IT disable WPAD where possible.






