Hackers are reportedly hijacking hotel and conference center Wi-Fi connections by altering DNS settings on network devices, then sending users to fake Microsoft 365 login pages. The goal appears to be simple credential theft: a traveler connects to what looks like a normal network, tries to sign in, and unknowingly hands over account details to attackers.

According to the report, the activity has been underway since at least June. By tampering with DNS, attackers can change where a web request goes without needing to visibly break the browsing experience, making the fake Microsoft 365 page look like a routine sign-in step for people checking email or work documents while away from the office.

The campaign highlights a risk that is especially relevant in shared public networks such as hotels and event venues. Business travelers, conference attendees, and remote workers often depend on these connections to access Microsoft 365 services, which makes a convincing fake login page an effective trap when users are in a hurry or distracted.

The incident is another reminder that public Wi-Fi threats are not limited to unsecured connections alone. In this case, the danger comes from network-level redirection combined with a familiar enterprise login target, creating a phishing setup that can capture Microsoft 365 credentials before users realize anything is wrong.