Hackers have been using compromised hotel and conference center Wi-Fi systems to steal Microsoft 365 credentials, according to research documented by ReliaQuest. The activity involved attackers taking over Wi-Fi gateways and redirecting internet users to fraudulent Microsoft 365 sign-in pages.
The tactic is notable because it abuses a network that travelers often see as a routine part of checking in or connecting at an event venue. Instead of relying only on email lures or fake websites found elsewhere online, the attackers reportedly inserted the phishing step directly into the internet access experience.
By placing a fake Microsoft 365 login page in front of users, the attackers aimed to capture usernames and passwords from people who believed they were completing a normal sign-in process. That makes hotel guests, conference attendees and business travelers particularly exposed if they connect through affected gateways and enter work account credentials.
The report highlights how public and semi-public Wi-Fi infrastructure can become part of credential theft campaigns when network equipment is compromised. It also underscores the continuing value of Microsoft 365 accounts to cybercriminals, especially when they can harvest access through trusted locations such as hotels and conference centers.