Hackers are reportedly targeting hotel and conference-center internet systems to push travelers toward counterfeit Microsoft 365 sign-in pages. The campaign turns a routine Wi-Fi connection into a possible credential trap, especially for people logging in to work accounts while on the road.

According to the report, attackers are interfering with Wi-Fi gateway equipment used to connect guests to the internet. Instead of seeing a normal access or login process, some users can be redirected to pages that appear to be legitimate Microsoft 365 screens, increasing the chance that usernames and passwords will be handed over to criminals.

The threat is notable because it is aimed at business travelers, a group that often relies on hotel Wi-Fi to access email, files and corporate tools. The description also says the fake login flow can bypass multifactor authentication, which raises the risk that even accounts with extra security enabled may still be exposed under the right conditions.

The incident highlights a broader cybersecurity problem with trusted public networks. Hotels and conference venues are common places for quick work logins, and that familiarity can make phishing attempts harder to spot when a fake page appears during the connection process.