Criminals are compromising public Wi-Fi routers at hotels and conference centers by changing their DNS settings, redirecting connected users to fake login pages designed to steal Microsoft 365 and other credentials.
Questions this post answers
How are attackers stealing Microsoft 365 credentials through hotel Wi-Fi?
Attackers compromise the Wi-Fi routers or access points at hotels and conference centers and alter their DNS settings, so that connected devices are silently redirected to fake login pages instead of legitimate sites. Victims who enter their Microsoft 365 credentials on these spoofed pages hand them directly to the attackers. Track emerging network-based phishing techniques like this one on daily.dev to protect users on untrusted networks.
120 Impressions