Hotel Wi-Fi DNS Hijacks Are Stealing Microsoft 365 Logins

What happened
Attackers are tampering with the DNS settings on Wi-Fi networking gear at hotels and conference centers, then quietly redirecting guests who try to reach Microsoft 365 to convincing fake login pages that harvest usernames, passwords, and session tokens. According to reporting from bleepingcomputer.com, the technique targets the hospitality network itself, so every guest on the compromised Wi-Fi can be pushed toward the attacker's infrastructure without any obvious warning sign.
The scenario is dangerous because it doesn't rely on a phishing email or a bad click. A traveler opens their laptop in a hotel lobby, sees the usual Microsoft 365 sign-in screen, and types in credentials. If the fake page proxies a real login in the background, even multi-factor authentication prompts can be relayed. The user gets in. So does the attacker.

Why this matters for Pittsburgh SMBs
If your team travels for depositions, client audits, industry conferences, plant visits, or DoD program reviews, this attack is aimed squarely at you. Pittsburgh has a heavy calendar of legal, accounting, healthcare, and manufacturing events, and our regional professionals routinely work from hotel rooms in Washington, Columbus, Philadelphia, and further afield. A single harvested Microsoft 365 credential from a partner or controller can lead to mailbox rules that intercept wire instructions, SharePoint data exfiltration, or a launch pad for ransomware inside your tenant.
The compliance stakes are just as real. For CPA firms and financial advisors under FTC Safeguards, a stolen M365 account touching client tax or brokerage data is a reportable incident. For medical practices, the same event is a probable HIPAA breach that starts a 60-day notification clock. For defense contractors working toward CMMC Level 2, an authentication compromise involving CUI is exactly the scenario your System Security Plan is supposed to prevent, and assessors will ask how you detected and contained it. "The hotel Wi-Fi did it" is not a defense.
One important caveat: the source reporting does not name specific hotel chains, hardware vendors, or geographic clusters. Rather than guess, assume the technique is portable and treat any untrusted network the same way.
What to do about it this week
You do not need a new tool stack to blunt this attack. You need a handful of disciplined habits and a couple of tenant-side controls verified by your IT team.
- Require the company VPN or a Secure Access Service Edge (SASE) tunnel on every laptop before any traffic leaves the device on hotel, airport, or conference Wi-Fi. Once the tunnel is up, DNS resolution happens over your controlled resolver, not the hotel's compromised one. If you don't have an always-on VPN profile pushed via managed IT, that's the first gap to close.
- Use a personal hotspot for anything sensitive. Modern carrier plans make tethering from a phone effectively free. For partner-level or finance-team travel, make it policy, not a suggestion.
- Move away from password + SMS/OTP toward phishing-resistant MFA. Windows Hello for Business, FIDO2 security keys, or Microsoft Authenticator with number matching and device-bound passkeys will not relay to an attacker-in-the-middle page the way a six-digit code will.
- Turn on Conditional Access policies that check device compliance and location. In Entra ID, require a Hybrid Azure AD joined or Intune-compliant device for M365 sign-in, and block or step-up legacy authentication and risky sign-ins. Verify with your admin whether your current licensing (Business Premium, E3 + P2, or E5) supports risk-based policies before you promise the board it's on.
- Train the road warriors specifically. A ten-minute briefing before conference season is worth more than an annual computer-based training module. Teach staff to recognize a captive portal versus a login page, to never enter M365 credentials right after joining a new network, and to close the lid and switch to a hotspot if anything looks off.
- Shorten sign-in session lifetimes for high-value roles. Partners, controllers, HR, and anyone with CUI access should be re-prompted more often, and their tokens should be revocable in one click. Confirm your break-glass and token-revocation runbook actually works.
- Review your incident response plan for a "credential theft on the road" scenario. Who revokes sessions in Entra? Who checks mailbox rules and OAuth app consents? Who notifies clients under HIPAA, SOC 2, or FTC Safeguards timelines? If a vCIO hasn't walked you through this in the last twelve months, schedule it.

How PGH Networks helps
We are a Pittsburgh MSP, and hardening M365 against exactly this class of attack is core to how we run cybersecurity, compliance, and IT strategy for local firms. That means Conditional Access tuned to your risk, phishing-resistant MFA rolled out without breaking your workflows, EDR/MDR watching your endpoints when they leave the office, and a documented response plan that satisfies your auditors and your clients. If your team is heading into fall conference and audit season, now is the time to close these gaps, not after a Monday-morning wire fraud call.
Talk to us
Call 724.888.7007 or reach out through the contact form and we'll walk your leadership team through a short M365 travel-risk review, no obligation.
Related reading

Pittsburgh CPA Firm Cybersecurity and Cloud Case Study
How a Pittsburgh accounting firm hardened cybersecurity, moved CCH and Lacerte to the cloud, and hit a GLBA-aligned WISP before tax season with PGH Networks.

Cloud Backup for Law Firms in Pittsburgh
Cloud backup for law firms in the Pittsburgh metro: matter-aware retention, PA Rule 1.6 confidentiality, ransomware recovery, and a local team on call.

Cloud Backup for Accounting Firms in Pittsburgh
Cloud backup for accounting firms in the Pittsburgh metro: protect tax files, QuickBooks, and client PII with encrypted, audit-ready recovery from PGH Networks.