Filed under: Cybersecurity — Phishing — July 2026

What happened

Researchers at ReliaQuest found attackers breaking into the Wi-Fi gateway devices at hotels and conference centers — across multiple U.S. cities plus India and Saudi Arabia — and quietly changing their DNS settings. Guests trying to sign into Microsoft 365 get silently redirected to convincing fake login pages (domains like m365-owa[.]com and ms365-live[.]com). In some cases the attackers go a step further and abuse a legitimate Microsoft sign-in feature called “device code” authentication, tricking the victim into approving what looks like a normal sign-in — which hands the attacker a live, already-approved session. No password is stolen and MFA is never actually challenged, because the attacker’s session was authorized by the victim directly.

Why it matters to your business

Any employee who checks email or OneDrive on hotel or conference Wi-Fi during a business trip is a potential target — the campaign has been hitting financial, legal, professional-services, healthcare, and retail firms without much pattern to who gets picked. A compromised mailbox means an attacker can read invoices, client files, and banking details, and send messages that look like they came from your own staff. This is squarely a summer-travel-season risk for any Phoenix business with people out at conferences, client visits, or trade shows.

What to do this week

Tell traveling staff to turn on a full-tunnel VPN before opening any browser or email app on hotel or conference Wi-Fi — never trust the network itself. In the Microsoft Entra admin center (entra.microsoft.com), go to Protection > Conditional Access > Policies > New policy, and under Conditions > Authentication flows, select “Device code flow” and set the grant to Block access unless a specific user genuinely needs it (e.g., certain IoT or CLI sign-ins). Also remind employees plainly: never approve a device sign-in code or MFA prompt unless you personally just typed it in on that exact device — if a prompt shows up out of nowhere, deny it and tell IT.

The bigger picture

This is another reminder that MFA alone isn’t the finish line — attackers are increasingly targeting the sign-in flow itself rather than the password. Locking down which authentication methods are even allowed matters as much as requiring MFA in the first place. Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Got staff traveling for business this summer? Book a free consult — https://micro1tech.com/contact/