Hackers are reportedly targeting hotel and conference venue internet systems to gain access to Microsoft 365 accounts used by traveling employees. The activity involves compromised captive Wi-Fi gateways and related portal devices, the kind that users typically see when they connect to public wireless networks and are asked to sign in through a browser page.

According to the report, the campaign has been active since at least June. Affected Wi-Fi infrastructure was identified in multiple cities in the United States, as well as in India and Saudi Arabia, suggesting a broad effort rather than a single local incident. The targets appear to include enterprise users connecting while on business travel.

The victims mentioned in the report came from companies in professional and financial services, legal work, and other business-focused sectors. That points to a practical goal for attackers: obtaining access to valuable corporate accounts by exploiting the trust users place in familiar hotel or conference center login pages.

The case is another reminder that public Wi-Fi can create serious security exposure, especially when travelers rely on convenient sign-in portals. For organizations using Microsoft 365, incidents like this highlight the risk of account takeover through compromised network equipment rather than only through traditional email phishing.