Fox News image for Hotel Wi-Fi phishing attack targets Microsoft logins - Fox News

💻 Technology · Fox News

Hotel Wi-Fi phishing attack targets Microsoft logins - Fox News

From Fox News via USVI News: Hackers are compromising hotel Wi-Fi gateways to redirect business travelers to fake Microsoft 365 login pages that can bypass multifactor authentication.

USVInews.com User Network Contributor

Fox News Flash top headlines are here. Check out what's clicking on FoxNews.com.

Hackers are tampering with Wi-Fi equipment at hotels and conference centers, turning an everyday internet connection into a path toward fake Microsoft 365 login pages. The hotel Wi-Fi phishing attack poses a particular risk to business travelers. You might connect before a meeting, open your laptop and see what appears to be a normal Microsoft sign-in screen. However, the hotel's compromised network may have quietly sent you to a page controlled by hackers.

Cybersecurity company ReliaQuest says the campaign has been active since at least June. Researchers found compromised Wi-Fi gateways in several U.S. cities. Organizations in financial services, professional services, legal, health care, energy and retail connected through the affected equipment. That broad range suggests the hackers may be targeting traveling employees rather than one specific industry. Here is how the attack works, which warning signs to watch for and the steps you can take to protect yourself while traveling.

CyberGuy Live: Missed "Sick of Spam?" Get the replay and checklist

Our free CyberGuy Live class, "Sick of Spam?", has ended, but you can still watch the full replay and download our spam-stopping checklist. Kurt "CyberGuy" Knutsson walks you step by step through simple ways to reduce robocalls, spam texts, junk email and unwanted messages. You’ll also learn how to curb political texts, clean up your inbox and spot messages that could put your personal information at risk.

Get the free replay and checklist now at CyberGuyLive.com.

FBI HELPS TAKE DOWN AI PHISHING RING

Hackers can hijack hotel Wi-Fi gateways and redirect travelers to fake Microsoft 365 login pages. (Kurt "CyberGuy" Knutsson)

Hackers are changing hotel Wi-Fi DNS settings

A Wi-Fi gateway controls how connected devices reach the internet. Once hackers gain administrative access, they can change the gateway's Domain Name System settings. DNS works like an address book for the internet. It translates a website name into the numerical address needed to reach the correct server.

In this campaign, hackers alter that process. When someone tries to open a legitimate Microsoft login page, the compromised gateway may direct the browser to a fake site instead. Your device can still appear connected normally. The hotel name may show up in your Wi-Fi settings and other websites may continue loading. That makes the attack difficult to notice before you enter sensitive information.

How attackers may be breaking into Wi-Fi gateways

ReliaQuest has not confirmed how the attackers first gained access to the affected appliances. However, the researchers identified several possible entry points. Some gateways may expose administrative tools directly to the internet. Hackers could search for weak passwords, vulnerable web dashboards or poorly protected remote management services.

Older Wi-Fi appliances may also run software with known security flaws. If a hotel or event venue delays an update, an attacker may exploit that opening and take control. Once inside, the hacker can change the DNS configuration without touching each guest's phone or laptop. One compromised gateway can affect many people who connect during an event.

A familiar hotel network can still send your laptop to a fraudulent sign-in site without an obvious warning. (Kurt "CyberGuy" Knutsson)

Fake Microsoft 365 pages capture business logins

ReliaQuest says the attackers registered at least four domains for the fake Microsoft portals:

- m365-owa[.]com

- owa-ms365[.]com

- ms365-device[.]com

- ms365-live[.]com

These addresses contain familiar Microsoft terms. A traveler moving quickly between meetings may overlook the unusual domain name. The fake page can collect a Microsoft 365 email address and password. A stolen account may expose business email, private documents and company cloud services. Hackers could also use the account to impersonate an employee. That creates opportunities for payment fraud, internal phishing or further attacks against coworkers and clients.

A device code prompt may bypass MFA

Some incidents involved a more deceptive device code authentication flow. A user reached a fake Microsoft page that displayed an authorization prompt. The prompt appeared to be part of a legitimate sign-in process.

This article is republished through the USVI News affiliate desk. Reporting, analysis, and viewpoints are those of the original publisher and do not necessarily reflect USVI News.

Read more at Fox News