411/69 Monday, July 27, 2026

Security researchers have disclosed an attack campaign targeting Wi-Fi systems at hotels, conference centers, and other venues providing public network access. The attackers take control of or modify Wi-Fi gateway settings to redirect users to fake Microsoft 365 login pages and steal account credentials from corporate employees connected through those networks. The campaign has reportedly been active since June 2026 and has been observed in several U.S. cities, as well as some locations in India and Saudi Arabia.
Reports indicate that attackers may gain access to Wi-Fi gateway devices through internet-exposed management interfaces, such as SSH, SNMP, or web administration consoles, combined with weak or reused passwords. They then modify DNS settings so that users attempting to access Microsoft 365 are redirected to attacker-controlled fake domains, such as m365-owa[.]com, ms365-device[.]com, and ms365-live[.]com. In some cases, researchers also observed attempts to use Web Proxy Auto-Discovery (WPAD) to configure a malicious proxy, as well as the use of the device-code authentication flow to trick users into approving the attacker’s login attempt. This could allow attackers to obtain OAuth tokens that have already passed MFA requirements without directly stealing passwords.
Organizations should require employee devices to use always-on, full-tunnel VPNs when connecting to public networks so that traffic and DNS requests are routed through trusted networks before reaching the internet. WPAD should be disabled if it is not required, and the device-code authentication flow in Microsoft Entra ID should be restricted or disabled where appropriate. Users should also verify URLs and website certificates before entering account credentials, especially when using Wi-Fi at hotels, airports, conference centers, or other public networks. In addition, organizations should monitor Microsoft 365 logins from unusual locations or devices, review suspicious OAuth token activity, and block domains or IP addresses associated with the campaign.
