Security researchers at ReliaQuest have been tracking a campaign that hijacks the Wi-Fi gateway devices used at hotels, conference centres, airports, co-working spaces and universities, then quietly rewrites their DNS settings. Guests who connect and open a browser get pointed, without any warning, to one of four lookalike Microsoft login pages — m365-owa.com, owa-ms365.com, ms365-device.com and ms365-live.com — that harvest whatever credentials get typed in. In a smaller number of cases, the attackers went further, abusing Microsoft Entra ID's device-code sign-in flow to obtain an already-MFA-approved access token, meaning they never needed a password at all.
The entry point, ReliaQuest assesses with low-to-medium confidence, is the same as it always is for this class of attack: gateway and captive-portal management interfaces — SSH, SNMP, web admin consoles — left exposed to the internet and protected by weak or reused administrator passwords. Compromised gateways have turned up across several US cities as well as in India and Saudi Arabia. The sectors named in the report — financial services, professional services, legal, healthcare, energy, retail — aren't the actual target; the researchers are clear this isn't sector-specific. Anyone whose staff travel and log into Microsoft 365 from venue Wi-Fi is exposed, regardless of what the company does.
The technique — poisoning DNS on compromised routers to run adversary-in-the-middle credential theft against Microsoft 365 — closely mirrors a pattern researchers previously tied to APT28 (also known as Forest Blizzard or Fancy Bear), a Russian state-linked group, in earlier campaigns against home and small-office routers. ReliaQuest is careful not to claim this hotel-focused campaign is the same operators: the domains, targeting and infrastructure differ enough that they describe it as tradecraft reuse rather than a confirmed link. Worth knowing as context, not worth repeating as attribution.
What this means for your business
- This is a travel risk, not an office risk. If nobody on your team logs into work accounts from hotel, conference, airport or co-working Wi-Fi, this specific campaign doesn't reach you. If they do, it does.
- Turn on the company VPN before opening a browser on venue Wi-Fi, not after. A full-tunnel VPN with its own DNS resolver means the hijacked gateway never gets to redirect the request in the first place.
- Ask whoever manages your Microsoft 365 tenant to check whether the device-code sign-in flow is enabled and switch it off unless something specific needs it (some TVs, kiosks and IoT devices use it) — most staff never need it day to day, and it's the piece that lets an attacker in without ever touching a password.
- Tell travelling staff plainly: don't trust a hotel or conference Wi-Fi login screen with a Microsoft password, and pay attention if a familiar login page suddenly looks slightly different — different logo placement, an unfamiliar domain in the address bar, an unexpected prompt to re-enter credentials mid-session.
- Review your Microsoft 365 sign-in logs for unfamiliar locations tied to any employee who has travelled recently, particularly sign-ins from IP ranges that don't match where that person actually was.
None of this requires a phishing email, a malicious attachment, or a moment of carelessness from the employee — just an internet connection at the wrong venue. That's exactly why a company VPN belongs on every travelling laptop as a default, not an optional extra.