Hotel Wi-Fi DNS poisoning is stealing Microsoft 365 logins
ReliaQuest found hotel Wi-Fi gateways poisoning DNS to hijack Microsoft 365 accounts — including a device-code trick that satisfies MFA without stealing a password.
Your salesperson connects to the Wi-Fi at a conference hotel. No phishing email, no attachment, nothing installed on the laptop. They sign into Outlook, and by the time they land at home the mailbox is being read by someone else. Hotel Wi-Fi DNS poisoning is an active campaign against Microsoft 365 accounts right now, and the worst version of it never asks for a password at all.
What actually happened
ReliaQuest published a threat spotlight documenting a campaign running since at least June 2026 against captive-portal Wi-Fi gateways at hotels and conference centers. The entry point is unglamorous: exposed management interfaces on the gateway combined with weak or reused admin credentials. Once attackers own the gateway, it is the DHCP-assigned DNS resolver for every guest, so it can forge answers. Requests for Microsoft domains resolve to attacker-run hosts — m365-owa[.]com, owa-ms365[.]com, ms365-device[.]com, ms365-live[.]com.
The fake login page is the boring half. Two other channels do the real damage. WPAD abuse quietly routes Windows application traffic through an attacker proxy. And on ms365-live[.]com, ReliaQuest documented abuse of Microsoft's device-code authentication flow: the attacker starts a sign-in, the victim approves the prompt, and the attacker's session is authorized. No password is stolen. No token is intercepted. MFA is satisfied, because a real human really did approve a real prompt.
ReliaQuest found compromised gateways in multiple US cities plus India and Saudi Arabia, with traffic from financial services, professional services, legal, health care, energy, and retail. They match the tradecraft to earlier APT28 router campaigns at low-to-medium confidence, and stop short of direct attribution — which is the honest way to say it.
Why hotel Wi-Fi DNS poisoning matters for your business
The uncomfortable part is that every control most small businesses actually bought gets bypassed here. Email filtering doesn't fire, because there's no email. Endpoint protection doesn't fire, because nothing runs. MFA doesn't fire, because the user approved it. The attack lives entirely in the network path between your employee and Microsoft, on infrastructure you don't own and can't audit.
So the fixes are configuration, not products. Turn off the device-code authentication flow in Entra ID Conditional Access unless something you run genuinely needs it — most companies never use it, and leaving it on is a free MFA bypass sitting in the tenant. Push an always-on, full-tunnel VPN so DNS resolution never happens on a stranger's gateway. Disable WPAD by Group Policy. And teach one rule that survives contact with a tired traveler: if a login prompt appears that you did not personally start, deny it.
Key takeaways
- ReliaQuest documented compromised hotel and conference Wi-Fi gateways poisoning DNS to redirect Microsoft 365 traffic, active since at least June 2026
- Spoofed domains included m365-owa[.]com and ms365-live[.]com; the gateway serves as the DNS resolver, so no phishing email is needed
- Device-code authentication abuse authorizes the attacker's session with the user's own approval — MFA is satisfied and no password is stolen
- For your business: disable device-code flow in Entra ID Conditional Access, enforce full-tunnel VPN, disable WPAD, and never approve a prompt you didn't start
Do you know if device-code auth is enabled in your tenant right now? Most owners don't, and it's a one-setting MFA bypass. We audit identity configuration and lock down the defaults that ship wide open. Have us review your Microsoft 365 tenant or see what else we harden.
Sources: ReliaQuest, BleepingComputer.
- #dns-poisoning
- #microsoft-365
- #mfa-bypass
- #device-code
- #travel-security
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Qualcomm's price increase hits your hardware budget
Qualcomm told customers of a double-digit price increase on chips shipped after September 1. The AI buildout is now repricing hardware that has nothing to do with AI.
Read it24,000 exposed BMCs leak hashes: close your IPMI port
A 2004 protocol flaw with no patch is handing out password hashes from 24,000 internet-exposed server BMCs. The fix is network exposure, not a firmware update.
Read it