A reported attack campaign is targeting travelers by tampering with hotel and conference-center Wi-Fi systems. Instead of relying on phishing emails or infected files, the attackers reportedly compromise the network gateway itself and then steer guests toward fake Microsoft 365 login pages.

That approach makes the threat stand out because victims do not need to click a suspicious link or install malware. If a user connects to the affected Wi-Fi network, the altered DNS behavior can send normal sign-in attempts to counterfeit Microsoft 365 infrastructure controlled by the attackers.

The title of the report indicates the method can also bypass multi-factor authentication for Microsoft 365 travelers. In practice, that raises concern for people working on the road, since hotel and event Wi-Fi are commonly used for email, document access and other cloud services tied to Microsoft 365 accounts.

The broader takeaway is that public-network trust is becoming part of the attack surface. When the Wi-Fi gateway is compromised, even routine login behavior can be turned into a credential-harvesting opportunity, making hotel and conference connectivity a higher-risk environment for business travelers.