Hackers have been tampering with Wi-Fi equipment at hotels and conference centers in several U.S. cities, turning routine internet connections into pathways to fake Microsoft 365 login pages. This phishing attack, active since at least June according to cybersecurity company ReliaQuest, poses a significant risk to business travelers who may unknowingly enter sensitive credentials.
Users connecting to compromised hotel Wi-Fi might see what appears to be a normal Microsoft sign-in screen before a meeting. However, the network may redirect them to a page controlled by hackers. One compromised gateway can affect many users during an event, making the attack difficult to detect.
This phishing technique can bypass multifactor authentication because the user completes the approval process, effectively allowing hackers to gain access despite additional security layers. Experts advise verifying any Microsoft authentication requests through the company's IT department before proceeding.
Kurt Knutsson, an award-winning tech journalist contributing to Fox News and FOX Business, reported on the issue and offered resources such as a replay and checklist from the CyberGuy Live class to help users protect themselves.
Loading comments.