As cited
Copy frozen at (site build).
threat intel
Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts
Attackers are modifying DNS settings on hotel and conference center Wi-Fi networks to redirect users to fraudulent Microsoft 365 login pages, capturing credentials in the process. This technique exploits the trusted nature of venue Wi-Fi to conduct large-scale phishing attacks against travelers and conference attendees. The attackers gain access to authentic Microsoft 365 accounts without triggering multi-factor authentication if users enter their credentials on the fake login page.
Why it matters: Business travelers and conference attendees using venue Wi-Fi are at immediate risk of account compromise; practitioners should warn users not to log in to sensitive services on public Wi-Fi and verify that hotels and conference centers implement DNS security controls and monitor for unauthorized changes to network settings.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts
Attackers are modifying DNS settings on hotel and conference center Wi-Fi networks to redirect users to fraudulent Microsoft 365 login pages, capturing credentials in the process. This technique exploits the trusted nature of venue Wi-Fi to conduct large-scale phishing attacks against travelers and conference attendees. The attackers gain access to authentic Microsoft 365 accounts without triggering multi-factor authentication if users enter their credentials on the fake login page.
Why it matters: Business travelers and conference attendees using venue Wi-Fi are at immediate risk of account compromise; practitioners should warn users not to log in to sensitive services on public Wi-Fi and verify that hotels and conference centers implement DNS security controls and monitor for unauthorized changes to network settings.
- Source published
- First seen by Cybersecurity Tracker