READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Hackers Are Hijacking Hotel Wi-Fi to Steal Microsoft Logins, Researchers Say

Hackers Are Hijacking Hotel Wi-Fi to Steal Microsoft Logins, Researchers Say
Cybersecurity firm ReliaQuest says hackers have been compromising Wi-Fi gateways at hotels and conference centers since at least June, quietly redirecting business travelers to fake Microsoft 365 login pages. The connection looks normal. It isn't. Business travelers should treat any hotel Wi-Fi login prompt with suspicion and use a VPN or personal hotspot instead.

Business travelers logging into Microsoft 365 from a hotel room may be handing their credentials straight to hackers, according to cybersecurity firm ReliaQuest.

The firm says a phishing campaign targeting hotel and conference center Wi-Fi equipment has been active since at least June 2026. Researchers identified compromised Wi-Fi gateways in several U.S. cities, according to ReliaQuest's findings as reported by Fox News.

How the Attack Works

A Wi-Fi gateway is the device that controls how everything connected to it reaches the internet. Once hackers gain administrative access to one, they can alter its Domain Name System settings, according to ReliaQuest.

DNS is the system that translates a website name, like microsoft.com, into the numerical address a browser needs to find the real server. Hijack the DNS settings on a gateway, and you can quietly reroute anyone using that network to a server you control instead, without them noticing anything is wrong.

In this campaign, when a hotel guest tries to open a legitimate Microsoft login page, the compromised gateway redirects the browser to a fake one built to look identical. The device still shows it's connected to the hotel's real Wi-Fi network. Other websites keep loading normally. Nothing about the connection looks broken, according to ReliaQuest's research.

What makes this particular attack dangerous is the lack of obvious warning signs. There's no broken padlock icon, no warning banner. The victim sees a Microsoft sign-in screen that looks exactly like the one they've used a hundred times, types in a username and password, and hands both straight to the attacker.

Who's Being Targeted

ReliaQuest found that organizations connecting through the affected equipment span financial services, professional services, legal, health care, energy and retail. That's a wide net.

The breadth of industries suggests the hackers aren't chasing one specific company or sector. They appear to be casting a wide net for traveling employees generally, regardless of who they work for, according to the ReliaQuest analysis cited by Fox News. A stolen Microsoft 365 login can be valuable no matter whose name is on the paycheck: email access, internal documents, calendar details and, in many corporate environments, a foothold into the broader company network.

How Hackers Got In

ReliaQuest has not confirmed exactly how the attackers first compromised the Wi-Fi gateways. But researchers pointed to several plausible entry points.

Some gateways expose administrative dashboards directly to the internet, meaning anyone who finds the login page can try to break in remotely. Others may simply run on weak or default passwords that were never changed after installation. Older equipment can also carry known software vulnerabilities that were never patched, particularly at smaller hotels or event venues that don't have dedicated IT security staff managing network hardware.

None of that requires a particularly sophisticated hacker. It requires an unmaintained piece of hardware sitting in a hotel basement.

What This Doesn't Prove, and What It Does

ReliaQuest has documented compromised gateways and a live phishing infrastructure aimed at Microsoft credentials. No specific hotel chain, conference organizer, or hardware manufacturer has been named as responsible or negligent in the available reporting. No breach notification, lawsuit, or regulatory action has been reported in connection with this campaign as of this writing.

What is established: this isn't a hypothetical vulnerability. It's an active campaign that researchers say has been running for roughly two months and has already touched networks used by people in industries handling sensitive financial, legal, and medical information.

What Travelers Can Actually Do

The practical defense is straightforward, even if it's inconvenient. Business travelers should be skeptical of any login page that appears immediately after connecting to hotel or venue Wi-Fi, especially one asking for a Microsoft 365 password. Checking that the URL in the address bar actually matches Microsoft's real domain, rather than a close lookalike, is a basic but effective check.

Using a personal mobile hotspot instead of hotel Wi-Fi for anything involving a company login removes the risk entirely, since the attack depends on the hotel's own network equipment being compromised. A VPN can add a layer of protection by encrypting traffic before it reaches a potentially hijacked gateway, though it isn't foolproof against every version of this attack.

Multi-factor authentication remains one of the strongest defenses, since a stolen password alone typically isn't enough to access an account if a second verification step is required. Fox News, drawing on cybersecurity commentator Kurt Knutsson's guidance, emphasized these same basic precautions: verify the URL, avoid entering credentials on unfamiliar networks, and treat hotel Wi-Fi as inherently less trustworthy than a home or office connection.

ReliaQuest has not said whether it has notified the affected hotels or venues, or whether any gateways have since been patched or replaced. That leaves an open question for the hospitality industry: how many other hotel networks are running the same unmaintained equipment, and who is responsible for finding out.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

right
Fox NewsHotel Wi-Fi phishing attack targets Microsoft logins