Hackers are compromising hotel Wi-Fi gateways to hijack Microsoft 365 accounts

Summary

Threat actors are compromising Wi-Fi gateways in hotels and conference centers to hijack Microsoft 365 accounts. Attackers use DNS poisoning to redirect users' traffic to fraudulent domains, stealing credentials without direct endpoint interaction. This tactic exploits the inherent trust users place in network gateways.

IFF Assessment

FOE

This article details a new attack vector that compromises user credentials, posing a direct threat to organizations and individuals by exploiting network infrastructure trust.

Defender Context

Defenders should be aware of the risks associated with public Wi-Fi and educate traveling employees about potential threats. Implementing strong multi-factor authentication for Microsoft 365 accounts can mitigate the impact of credential theft, even if network traffic is compromised.

Read Full Story →